Critical severity9.8NVD Advisory· Published Nov 28, 2023· Updated Jun 17, 2026
CVE-2023-41264
CVE-2023-41264
Description
Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to privilege escalation. This only occurs if the configuration omits the required restSettings.AuthorizedClientId and restSettings.AuthorizedSecret fields (for the POST /api/Deployment/ExportConfiguration and POST /api/Deployment endpoints).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Netwrix/Usercubedescription
Patches
Vulnerability mechanics
References
2- www.synacktiv.com/advisories/usercube-netwrix-multiple-vulnerabilitiesnvdExploitThird Party Advisory
- www.netwrix.com/identity_governance_and_administration_solution.htmlnvdProduct
News mentions
0No linked articles in our index yet.