CVE-2026-72564: fosrl Pangolin - Access Token Scope Bypass Allows Cross-Resource Authentication
An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued for a different resource.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72564?
The severity of CVE-2026-72564 is critical with a score of 9.6.
What does CVE-2026-72564 involve?
CVE-2026-72564 involves an improper authorization vulnerability that allows an authenticated remote attacker to misuse an access token to authenticate to any resource.
How do I fix CVE-2026-72564?
To fix CVE-2026-72564, update to the latest version of fosrl/pangolin beyond v1.20.0 that addresses this vulnerability.
What impact does CVE-2026-72564 have on system security?
CVE-2026-72564 can lead to unauthorized access to any resources within an organization, compromising the system's security.
Who is affected by CVE-2026-72564?
Organizations using fosrl/pangolin versions prior to v1.20.0 are affected by CVE-2026-72564.