CVE-2026-6571: kodcloud KodExplorer systemRole.class.php roleGroupAction authorization
A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipulation of the argument grouprole can lead to authorization bypass. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6571?
CVE-2026-6571 is considered a medium severity vulnerability in kodcloud KodExplorer.
How do I fix CVE-2026-6571?
To fix CVE-2026-6571, upgrade kodcloud KodExplorer to version 4.53 or later.
What impact does CVE-2026-6571 have on my system?
CVE-2026-6571 allows an attacker to manipulate authorization parameters, potentially leading to unauthorized access.
Which versions of KodExplorer are affected by CVE-2026-6571?
CVE-2026-6571 affects kodcloud KodExplorer versions up to and including 4.52.
Who is the vendor for CVE-2026-6571?
The vendor for CVE-2026-6571 is kodcloud, the developer of KodExplorer.