Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 16 Aug 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a manipulation can lead to improper privilege management. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.9.8-hotfix1 and 0.9.8 mitigates this issue. This patch is called 788cace0af816aa972a713a4631c57f16f895e6b. Upgrading the affected component is recommended. | |
| Title | OpenBoxes Role Interceptor RoleInterceptor.groovy needManager privileges management | |
| First Time appeared |
Openboxes
Openboxes openboxes |
|
| Weaknesses | CWE-266 CWE-269 |
|
| CPEs | cpe:2.3:a:openboxes:openboxes:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openboxes
Openboxes openboxes |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-16T02:45:12.102Z
Reserved: 2026-08-15T05:46:50.788Z
Link: CVE-2026-19928
No data.
Status : Received
Published: 2026-08-16T03:16:50.143
Modified: 2026-08-16T03:16:50.143
Link: CVE-2026-19928
No data.
OpenCVE Enrichment
Updated: 2026-08-16T10:15:17Z