PatchSiren cyber security CVE debrief
CVE-2026-38470 Mosasauroidea CVE debrief
A Broken Access Control vulnerability exists in GazellePW's API user endpoint, allowing authenticated users with normal privileges to enable or disable arbitrary user accounts using a user-created API token with req=disable or req=enable actions. This medium-severity issue has a CVSS score of 4.3 and affects GazellePW. Developers and administrators of GazellePW, security teams monitoring for access control issues, and users of GazellePW should be aware of this vulnerability and take necessary actions to mitigate the risk. The CVE Program and NVD provide official records of the vulnerability.
- Vendor
- Mosasauroidea
- Product
- GazellePW
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-08-31
Who should care
Developers and administrators of GazellePW, security teams monitoring for access control issues, and users of GazellePW should be aware of this vulnerability and take necessary actions to mitigate the risk. The vulnerability allows unprivileged, authenticated users to enable or disable arbitrary user accounts via the req=disable or req=enable action using a normal user-created API token. The CVE Program and NVD provide official records of the vulnerability. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The affected product is GazellePW, and the vulnerability was published on 2026-08-25T22:17:03.663Z. The CVE record has not been modified since then. The vulnerability allows unprivileged, authenticated users to enable or disable arbitrary user accounts via the req=disable or req=enable action using a normal user-created API token. The CVE Program and NVD provide official records of the vulnerability. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The affected product is GazellePW, and the vulnerability was published on 2026-08-25T22:17:03.663Z. The CVE record has not been modified since then. The vulnerability allows unprivileged, authenticated users to enable or disable arbitrary user accounts via the req=disable or req=enable action using a normal user-created API token. The CVE Program and NVD provide official records of the vulnerability. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The affected product is GazellePW, and the vulnerability was published on 2026-08-25T22:17:03.663Z. The CVE record has not been modified since then. The vulnerability allows unprivileged, authenticated users to enable or disable arbitrary user accounts via the req=disable or req=enable action using a normal user-created API token. The CVE Program and NVD provide official records of the vulnerability. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The affected product is GazellePW, and the vulnerability was published on 2026-08-25T22:17:03.663Z. The CVE record has not been modified since then. The vulnerability allows unprivileged, authenticated users to enable or disable arbitrary user accounts.
Technical summary
A Broken Access Control vulnerability exists in GazellePW's API user endpoint. Authenticated users with normal privileges can enable or disable arbitrary user accounts using a user-created API token with req=disable or req=enable actions. This vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The affected product is GazellePW, and the vulnerability was published on 2026-08-25T22:17:03.663Z.
Defensive priority
Authenticated users with low privileges can manipulate user accounts, indicating a medium-severity access control issue.
Recommended defensive actions
- Review and restrict API token permissions for user account management
- Implement additional access controls and monitoring for user account changes
- Verify and limit the use of req=disable and req=enable actions in API requests
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE details a Broken Access Control vulnerability in GazellePW's API user endpoint, allowing authenticated users to enable or disable arbitrary user accounts. Official records from CVE and NVD provide the primary source information. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The affected product is GazellePW, and the vulnerability was published on 2026-08-25T22:17:03.663Z. The CVE record has not been modified since then. The vulnerability allows unprivileged, authenticated users to enable or disable arbitrary user accounts via the req=disable or req=enable action using a normal user-created API token. The CVE Program and NVD provide official records of the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-38470 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-38470
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-38470 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-38470
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Mosasauroidea/GazellePW/blob/86c4bedf727691b5a97af42a4864869d18446449/app/API/User.php
-
Source reference
Unverified legacy reference
URL: https://snaacky.com/1-click-exploit-chain-for-complete-gazellepw-database-compromise
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.