A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipulation of the argument group_role can lead to authorization bypass. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Sun, 19 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipulation of the argument group_role can lead to authorization bypass. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | kodcloud KodExplorer systemRole.class.php roleGroupAction authorization | |
| First Time appeared |
Kodcloud
Kodcloud kodexplorer |
|
| Weaknesses | CWE-285 CWE-639 |
|
| CPEs | cpe:2.3:a:kodcloud:kodexplorer:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kodcloud
Kodcloud kodexplorer |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-04-19T12:00:17.810Z
Updated: 2026-04-19T12:00:17.810Z
Reserved: 2026-04-18T19:07:03.225Z
Link: CVE-2026-6571
No data.
Status : Received
Published: 2026-04-19T12:16:33.607
Modified: 2026-04-19T12:16:33.607
Link: CVE-2026-6571
No data.