PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-42571 PelicanPlatform CVE debrief

CVE-2026-42571 is a critical access-control flaw in Pelican's Web User Interface (WebUI). In affected releases, a user authenticated to the WebUI via OAuth can escalate to admin privileges under certain configurations. Fixed releases are 7.21.5, 7.22.3, 7.23.3, and 7.24.2.

Vendor
PelicanPlatform
Product
pelican
CVSS
CRITICAL 9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-09
Original CVE updated
2026-07-24
Advisory published
2026-05-09
Advisory updated
2026-07-24

Who should care

Administrators and operators running Pelican WebUI, especially deployments that allow OAuth-based authentication and rely on WebUI role separation. Security teams should treat this as a high-priority authentication and authorization issue.

Technical summary

The provided advisory describes a privilege escalation vulnerability in Pelican WebUI mapped to CWE-863 (incorrect authorization). The issue affects versions 7.21.0 through before 7.21.5, 7.22.0 through before 7.22.3, 7.23.0 through before 7.23.3, and 7.24.0 through before 7.24.2. According to the description, an authenticated OAuth user can gain admin privileges when the vulnerable configuration is present. NVD lists the vulnerability with a CVSS v4.0 score of 9.0 and impact across confidentiality, integrity, and availability.

Defensive priority

Immediate. This is a critical privilege escalation in a management interface, with authenticated access as the starting point. Prioritize patching and access review now.

Recommended defensive actions

  • Upgrade Pelican to 7.21.5, 7.22.3, 7.23.3, or 7.24.2, or later in the relevant release line.
  • Review WebUI OAuth authentication and authorization settings to confirm only intended users can reach administrative functions.
  • Audit existing WebUI admin accounts and recent privilege changes for unexpected elevation.
  • If immediate upgrading is not possible, restrict access to the WebUI to trusted administrative networks until remediation is complete.

Evidence notes

This debrief is based only on the supplied CVE/NVD record and the GitHub advisory references. The source description explicitly states the affected versions, the OAuth-authenticated privilege escalation condition, the fixed versions, and the CWE-863 mapping. No additional behavioral details are inferred beyond those sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-42571 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-42571

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-42571 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42571

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.