Back to overview

CVE-2026-63102

MEDIUM
5.4
CVSS 3.1
Description
rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. Attackers can exploit the missing allowlist validation and absent admin-level authorization check in StoreUserRequest to mass-assign the Admin role directly to the User model, granting access to privileged features. rConfig Pro and Enterprise are not affected.

Metadata

CVE ID
CVE-2026-63102
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-07-15 15:45 UTC
Published
2026-07-20 15:31 UTC
Last updated
2026-07-20 19:28 UTC
Primary CWE
CWE-915
Improperly Controlled Modification of Dynamically-Determined…
Vendor / Product
rConfig / rConfig v8 Core
Sources
cve.org  ·  NVD

Severity & Metrics

5.4 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
rConfig rConfig v8 Core 0 < 8.2.8
Weakness (CWE)
CWESourceDescription
CWE-915 cna Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVSS scores (2)
ScoreSeverityVersionSourceVector
5.4 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
5.3 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Back to overview