No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 16 Aug 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a manipulation can lead to improper privilege management. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.9.8-hotfix1 and 0.9.8 mitigates this issue. This patch is called 788cace0af816aa972a713a4631c57f16f895e6b. Upgrading the affected component is recommended. | |
| Title | OpenBoxes Role Interceptor RoleInterceptor.groovy needManager privileges management | |
| First Time appeared |
Openboxes
Openboxes openboxes |
|
| Weaknesses | CWE-266 CWE-269 |
|
| CPEs | cpe:2.3:a:openboxes:openboxes:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openboxes
Openboxes openboxes |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-16T02:45:12.102Z
Reserved: 2026-08-15T05:46:50.788Z
Link: CVE-2026-19928
No data.
Status : Received
Published: 2026-08-16T03:16:50.143
Modified: 2026-08-16T03:16:50.143
Link: CVE-2026-19928
No data.
OpenCVE Enrichment
Updated: 2026-08-16T04:30:03Z