High severity7.7NVD Advisory· Published Jun 26, 2026· Updated Jul 2, 2026
CVE-2026-57920
CVE-2026-57920
Description
Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.
Affected products
2- Range: <2.14.2 before 2026-06-03
Patches
Vulnerability mechanics
References
1- drive.google.com/file/d/1MoZn73YkDGGpqOgaQbRU1hWVygr8VaxY/viewnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.