← back
CVE-2026-72564criticalCWE-639

fosrl Pangolin - Access Token Scope Bypass Allows Cross-Resource Authentication

25Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.6
exploitation probability
observed exploitation
nono source reports it
An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued for a different resource.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Affected products
fosrl · Pangolin