Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/Peppermint-Lab/peppermint |
|
Thu, 13 Aug 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Peppermint
Peppermint peppermint |
|
| Vendors & Products |
Peppermint
Peppermint peppermint |
Thu, 13 Aug 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to false, causing all permission checks on ticket, client, and user handlers to behave as no-ops on default installations. All authenticated users bypass ownership and administrative access controls. An attacker with any user account can read, modify, or delete tickets, clients, and users belonging to any other account. | |
| Title | Peppermint Lab Peppermint - Broken Access Control | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-11T15:17:45.232Z
Reserved: 2026-08-10T10:32:49.081Z
Link: CVE-2026-72555
Updated: 2026-08-11T15:17:41.547Z
Status : Received
Published: 2026-08-11T12:17:41.240
Modified: 2026-08-11T16:17:35.897
Link: CVE-2026-72555
No data.
OpenCVE Enrichment
Updated: 2026-08-13T10:45:03Z