PT-2026-22837 · Unknown · Openstamanager

Runprogram

·

Published

2026-03-03

·

Updated

2026-03-05

·

CVE-2026-27012

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSTAManager versions 2.9.8 and earlier
Description OpenSTAManager is a management software for technical assistance and invoicing. A privilege escalation and authentication bypass exists in versions 2.9.8 and earlier, allowing an attacker to arbitrarily change a user's group (idgruppo) by directly calling the modules/utenti/actions.php endpoint. This can promote an existing account, such as an agent, to the Amministratori group, or demote any user, including existing administrators.
Recommendations Versions prior to 2.9.8 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27012
GHSA-247V-7CW6-Q57V

Affected Products

Openstamanager