CRITICAL
fosrl
CVE published 2026-08-10
CVE-2026-72564
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T11:17:28.837Z and has not been modified since then. This critical improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to reuse an access token issued for a different resource to authenticate to any resource in any organization. Security t [truncated]