PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-38470 Mosasauroidea CVE debrief

A Broken Access Control vulnerability exists in GazellePW's API user endpoint, allowing authenticated users with normal privileges to enable or disable arbitrary user accounts using a user-created API token with req=disable or req=enable actions. This medium-severity issue has a CVSS score of 4.3 and affects GazellePW. Developers and administrators of GazellePW, security teams monitoring for access control issues, and users of GazellePW should be aware of this vulnerability and take necessary actions to mitigate the risk. The CVE Program and NVD provide official records of the vulnerability.

Vendor
Mosasauroidea
Product
GazellePW
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-25
Original CVE updated
2026-08-31
Advisory published
2026-08-25
Advisory updated
2026-08-31

Who should care

Developers and administrators of GazellePW, security teams monitoring for access control issues, and users of GazellePW should be aware of this vulnerability and take necessary actions to mitigate the risk. The vulnerability allows unprivileged, authenticated users to enable or disable arbitrary user accounts via the req=disable or req=enable action using a normal user-created API token. The CVE Program and NVD provide official records of the vulnerability. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The affected product is GazellePW, and the vulnerability was published on 2026-08-25T22:17:03.663Z. The CVE record has not been modified since then. The vulnerability allows unprivileged, authenticated users to enable or disable arbitrary user accounts via the req=disable or req=enable action using a normal user-created API token. The CVE Program and NVD provide official records of the vulnerability. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The affected product is GazellePW, and the vulnerability was published on 2026-08-25T22:17:03.663Z. The CVE record has not been modified since then. The vulnerability allows unprivileged, authenticated users to enable or disable arbitrary user accounts via the req=disable or req=enable action using a normal user-created API token. The CVE Program and NVD provide official records of the vulnerability. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The affected product is GazellePW, and the vulnerability was published on 2026-08-25T22:17:03.663Z. The CVE record has not been modified since then. The vulnerability allows unprivileged, authenticated users to enable or disable arbitrary user accounts via the req=disable or req=enable action using a normal user-created API token. The CVE Program and NVD provide official records of the vulnerability. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The affected product is GazellePW, and the vulnerability was published on 2026-08-25T22:17:03.663Z. The CVE record has not been modified since then. The vulnerability allows unprivileged, authenticated users to enable or disable arbitrary user accounts.

Technical summary

A Broken Access Control vulnerability exists in GazellePW's API user endpoint. Authenticated users with normal privileges can enable or disable arbitrary user accounts using a user-created API token with req=disable or req=enable actions. This vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The affected product is GazellePW, and the vulnerability was published on 2026-08-25T22:17:03.663Z.

Defensive priority

Authenticated users with low privileges can manipulate user accounts, indicating a medium-severity access control issue.

Recommended defensive actions

  • Review and restrict API token permissions for user account management
  • Implement additional access controls and monitoring for user account changes
  • Verify and limit the use of req=disable and req=enable actions in API requests
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE details a Broken Access Control vulnerability in GazellePW's API user endpoint, allowing authenticated users to enable or disable arbitrary user accounts. Official records from CVE and NVD provide the primary source information. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The affected product is GazellePW, and the vulnerability was published on 2026-08-25T22:17:03.663Z. The CVE record has not been modified since then. The vulnerability allows unprivileged, authenticated users to enable or disable arbitrary user accounts via the req=disable or req=enable action using a normal user-created API token. The CVE Program and NVD provide official records of the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-38470 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-38470

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-38470 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-38470

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.