What is CVE-2026-19928?
An improper privilege management vulnerability exists in OpenBoxes up to version 0.9.7 within the `needManager` function in the `RoleInterceptor.groovy` file. Exploiting this flaw through manipulation could allow an attacker to gain unauthorized access. Users are advised to restrict access to the affected component until a security patch is applied.
Azərbaycanca: OpenBoxes (0.9.7-yə qədər) platformasında `RoleInterceptor.groovy` faylındakı `needManager` funksiyasında düzgün olmayan imtiyaz idarəetməsi (improper privilege management) zəifliyi aşkarlanıb. Bu, təcavüzkara manipulyasiya yolu ilə səlahiyyətsiz giriş əldə etməyə imkan verə bilər. İstifadəçilərə təhlükəsizlik yaması tətbiq edilənə qədər komponentə girişi məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Which versions of OpenBoxes are affected by CVE-2026-19928?
CVE-2026-19928 affects OpenBoxes versions up to 0.9.7.
What outcome can an attacker achieve by exploiting CVE-2026-19928?
An attacker exploiting this vulnerability could gain unauthorized access through manipulation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.