Back to CVE List

CVE-2026-42571

CRITICAL SEVERITY

Vulnerability Description

Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.24.0 to before 7.24.2, there is a a privilege escalation vulnerability affecting Pelican's Web User Interface (WebUI). This attack allows any user authenticated to the WebUI via OAuth to gain admin privileges under certain configurations. This issue has been patched in versions 7.21.5, 7.22.3, 7.23.3, and 7.24.2.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-863
Source
GitHub
Vendor
go
Product
github.com/pelicanplatform/pelican

External References

Discussion (0)

Add Comment

No comments yet. Be the first!