CVSS
6.3
CVSS v3.1
EPSS
N/A
Exploit Prediction Score
Published
August 16, 2026
Exploitability
No EPSS data available
A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a manipulation can lead to improper privilege management. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.9.8-hotfix1 and 0.9.8 mitigates this issue. This patch is called 788cace0af816aa972a713a4631c57f16f895e6b. Upgrading the affected component is recommended.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).