SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-38474

MEDIUM · CVSS 5.4 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A broken access control vulnerability in GazellePW's IP lock manager allows remote authenticated users to manipulate IP lock entries for any account through the tools.php?action=iplock interface. This could lead to unauthorized access and potential account compromise. Organizations using GazellePW should prioritize addressing this vulnerability to safeguard user accounts and maintain system integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-38474
Severity
MEDIUM
CVSS
5.4
EPSS
0.36%

Original NVD Description

GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 suffers from a Broken access control vulnerability in the IP lock manager, which allows remote authenticated users to add, modify, or delete IP lock entries for arbitrary accounts via tools.php?action=iplock.