PT-2026-38920 · Cashdro 3 · Cashdro 3
Peter Gabaldon
·
Published
2026-05-08
·
Updated
2026-05-09
·
CVE-2026-8077
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CashDro 3 version 24.01.00.26
Description
The web administration panel contains an authorization bypass due to a lack of backend authorization controls, which relies solely on the frontend for security. An attacker can escalate privileges and gain full administrative access by modifying the binary string in the
Permissions field of the JSON response. This allows all restrictions to be bypassed and compromises system management.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cashdro 3