SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-38470

MEDIUM · CVSS 4.3 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A broken access control vulnerability in the API user endpoint of GazellePW allows unprivileged, authenticated users to enable or disable any user account using a standard user-created API token. This could lead to unauthorized account management, potentially compromising user data and access. Organizations utilizing GazellePW should prioritize addressing this vulnerability to prevent potential misuse of user accounts.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-38470
Severity
MEDIUM
CVSS
4.3
EPSS
0.32%

Original NVD Description

A Broken access control vulnerability in the API user endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows unprivileged, authenticated users to enable or disable arbitrary user accounts via the req=disable or req=enable action using a normal user-created API token.