ExploitMatch
Back

CVE-2026-17601

Monitor on ThreatCluster

Description

A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or role reassignment.