AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:42.073Z and has not been modified since then. The broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the platform global OIDC/SSO settings via an unprotected configuration endpoint. The endp [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:41.240Z and has not been modified since then. A broken access control vulnerability exists in Peppermint Lab Peppermint through commit ba6e217. The Config.roles_active flag defaults to false, causing all permission checks on ticket, client, and user handlers to behave as no-ops. Authenticat [truncated]