PT-2026-38643 · Eladmin · Eladmin

Alices614

·

Published

2026-05-08

·

Updated

2026-05-10

·

CVE-2026-8127

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions eladmin versions prior to 2.8
Description Improper access controls in the Users API Endpoint allow for remote attacks. The issue exists within the checkLevel() function located in the /rest/UserController.java file.
Recommendations As a temporary workaround, restrict access to the Users API Endpoint or the checkLevel() function until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Privilege Assignment

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8127

Affected Products

Eladmin