Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-81294: Authorizer up to 3.15.1 lets anyone gain admin rights

CVE-2026-81294 · published 1 day ago
Summary

Versions of the Authorizer product up to 3.15.1 allow a person without any credentials to elevate their access to full administrative control. This means an attacker could change settings, view or delete data, and potentially disrupt services. Apply the latest update from the vendor as soon as possible or restrict network access to the application until it is patched.

What to do
  • Update paul ryan authorizer to version 3.15.2.
Affected software
VendorProductAffected versions
paul ryan authorizer <= 3.15.1
Fix: upgrade to 3.15.2
Original advisory text
Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Type
CWE-266Incorrect Privilege Assignment
Timeline
Published2 Sep 2026
Updated2 Sep 2026
First seen2 Sep 2026
Sources
CVE-2026-81294 · MITRE
Monitor software like this
Free during beta