HIGHVulnerability

CVE-2026-72555

A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to false, causing all permission checks on ticket, client, and user handlers to behave as no-ops on default installations. All authenticated users bypass ownership and administrative access controls. An attacker with any user account can read, modify, or delete tickets, clients, and users belonging to any other account.

Properties

severity
HIGH
score
8.1
epss_score
0.00263
cve_id
CVE-2026-72555
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
published_at
2026-08-11T12:17:41.240
last_modified
2026-09-03T17:51:18.670
epss_percentile
0.17888

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Access Control

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72555 — Ninja Signal Threat Intelligence | Ninja Signal