PT-2026-61621 · Unknown · Rconfig Core

·

CVE-2026-63102

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions rConfig Core versions prior to 8.2.8
Description Authenticated users can escalate privileges by assigning arbitrary roles to any account. This occurs when an unvalidated role field is submitted through the Users API during user creation or profile updates. The issue stems from missing allowlist validation and the absence of admin-level authorization checks in the StoreUserRequest function, allowing the Admin role to be mass-assigned directly to the User model.
Recommendations Update rConfig Core to version 8.2.8 or later. As a temporary mitigation, restrict access to the Users API to prevent unauthorized profile updates or user creation.

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63102

Affected Products

Rconfig Core