CVE-2026-103470: Critical severity Internet2 Grouper vulnerability
In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Internet2 Grouperto a version that resolves this vulnerability.Fixed in 7.5.1
Event History
Frequently Asked Questions
Who can exploit this issue?
A user who is permitted to create or edit rules through the Grouper User Interface can potentially escalate privileges. The issue applies only in some configurations.
Which deployments are affected?
Internet2 Grouper versions before 7.5.1 may be affected, depending on configuration. The available information does not identify the specific configurations involved.
What is the remediation?
Upgrade Internet2 Grouper to version 7.5.1 or later. If an immediate upgrade is not possible, review and restrict which users can create or edit rules in the User Interface.