A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to false, causing all permission checks on ticket, client, and user handlers to behave as no-ops on default installations. All authenticated users bypass ownership and administrative access controls. An attacker with any user account can read, modify, or delete tickets, clients, and users belonging to any other account.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/Peppermint-Lab/peppermint |
|
History
Thu, 13 Aug 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to false, causing all permission checks on ticket, client, and user handlers to behave as no-ops on default installations. All authenticated users bypass ownership and administrative access controls. An attacker with any user account can read, modify, or delete tickets, clients, and users belonging to any other account. | |
| Title | Peppermint Lab Peppermint - Broken Access Control | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-11T15:17:45.232Z
Reserved: 2026-08-10T10:32:49.081Z
Link: CVE-2026-72555
Updated: 2026-08-11T15:17:41.547Z
Status : Received
Published: 2026-08-11T12:17:41.240
Modified: 2026-08-11T16:17:35.897
Link: CVE-2026-72555
No data.
OpenCVE Enrichment
Updated: 2026-08-11T17:00:11Z