PT-2026-38643 · Eladmin · Eladmin

·

CVE-2026-8127

·

Published

2026-05-08

·

Updated

2026-05-10

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions eladmin versions prior to 2.8
Description Improper access controls in the Users API Endpoint allow for remote attacks. The issue exists within the checkLevel() function located in the /rest/UserController.java file.
Recommendations As a temporary workaround, restrict access to the Users API Endpoint or the checkLevel() function until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8127

Affected Products

Eladmin