CVE-2026-103470

Summary

In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.

Affected Software

VendorProductVersion RangeStatus
Internet2Grouper5.8.3 <= 5.22.5affected
Internet2Grouper6.0.0 < 6.4.1affected
Internet2Grouper7.0.0 < 7.5.1affected

Weaknesses

  • CWE-266: CWE-266 Incorrect Privilege Assignment

Workarounds

Turn off rules in UI for non-admins

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References