Medium severity5.4NVD Advisory· Published Jul 20, 2026· Updated Aug 19, 2026
CVE-2026-63102
CVE-2026-63102
Description
rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. Attackers can exploit the missing allowlist validation and absent admin-level authorization check in StoreUserRequest to mass-assign the Admin role directly to the User model, granting access to privileged features. rConfig Pro and Enterprise are not affected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/rconfig/rconfig/commit/84822f4051ed97d651b1b4d191c6da2aa8c3c037nvdPatch
- github.com/rconfig/rconfig/pull/325nvdIssue TrackingPatch
- www.vulncheck.com/advisories/rconfig-privilege-escalation-via-users-api-role-fieldnvdPatchRelease NotesThird Party Advisory
- github.com/rconfig/rconfig/releases/tag/core-8.2.8nvdProductRelease Notes
News mentions
0No linked articles in our index yet.