CVE-2026-92753: PatrowlManager through 1.8.4 Authorization Bypass via Events API
PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modify alerts belonging to other users.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated PatrowlManager user can exploit the affected events and alerts API endpoints. The attacker needs only low-level privileges and does not need user interaction.
What can an attacker do through the affected endpoints?
An attacker can read platform event history, delete arbitrary events, and modify alerts owned by other users. The impact includes disclosure of event data and unauthorized changes to alert and event records.
Which versions are affected?
PatrowlManager through version 1.8.4 is affected. The provided data does not identify a fixed version.