What is CVE-2026-72564?
CVE-2026-72564 is an improper authorization vulnerability in fosrl/pangolin up to version 1.20.0. It allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued for a different resource. Users should immediately update to a patched version.
Azərbaycanca: CVE-2026-72564, fosrl/pangolin-in 1.20.0 versiyasına qədər olan autentifikasiya mexanizmində `improper authorization` zəifliyidir. Bu, autentifikasiya olunmuş uzaqdan hücumçuya bir resurs üçün verilmiş `access token`-i təkrar istifadə edərək istənilən təşkilatdakı resurslara icazəsiz giriş imkanı yaradır. İstifadəçilərə dərhal proqramı yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What product is affected by CVE-2026-72564?
This vulnerability affects fosrl/pangolin up to version 1.20.0.
What can an attacker achieve by exploiting CVE-2026-72564?
An authenticated remote attacker can gain unauthorized access to resources in any organization by reusing an access token issued for a different resource.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.