PT-2026-22837 · Unknown · Openstamanager
Runprogram
·
Published
2026-03-03
·
Updated
2026-03-05
·
CVE-2026-27012
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSTAManager versions 2.9.8 and earlier
Description
OpenSTAManager is a management software for technical assistance and invoicing. A privilege escalation and authentication bypass exists in versions 2.9.8 and earlier, allowing an attacker to arbitrarily change a user's group (
idgruppo) by directly calling the modules/utenti/actions.php endpoint. This can promote an existing account, such as an agent, to the Amministratori group, or demote any user, including existing administrators.Recommendations
Versions prior to 2.9.8 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstamanager