PT-2026-38920 · Cashdro 3 · Cashdro 3

Peter Gabaldon

·

Published

2026-05-08

·

Updated

2026-05-09

·

CVE-2026-8077

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CashDro 3 version 24.01.00.26
Description The web administration panel contains an authorization bypass due to a lack of backend authorization controls, which relies solely on the frontend for security. An attacker can escalate privileges and gain full administrative access by modifying the binary string in the Permissions field of the JSON response. This allows all restrictions to be bypassed and compromises system management.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-8077

Affected Products

Cashdro 3