Executive brief
Pelican is a data federation platform used to manage distributed storage and compute resources across scientific institutions. This vulnerability allows any authenticated user (via OAuth login) to escalate to administrator privileges under specific server configurations. An attacker with admin access can modify server configuration to redirect traffic, impersonate trusted data paths, expose protected data, or deny service to the entire federation—potentially affecting hundreds of connected institutions and organizations.
Technical details
The vulnerability is a privilege escalation in Pelican's WebUI affecting versions v7.21 through v7.24 (Go module versions before 0.0.0-20260408120501-7f73b9c3e677). The root cause is insecure handling of database records for admin user and group membership configuration. When Server.UIAdminUsers or Server.AdminGroups are configured, the server fails to properly validate admin identities before granting privileges. An attacker with any authenticated OAuth session can craft database records that cause the server to grant them admin access on the next login. Attack preconditions include: (1) OIDC login enabled, (2) valid authenticated session, and (3) knowledge of an admin identifier (username or group name) that has not previously logged in. Exploitation grants full admin access, allowing configuration modification, API token creation, and password reset. The fix is available in versions ≥v7.21.5, ≥v7.22.3, ≥v7.23.3, and ≥v7.24.2. No evidence of wild exploitation in OSDF-operated services has been identified.
Affected products
- PelicanPlatform Pelican v7.21 through v7.24 (before v7.21.5, v7.22.3, v7.23.3, v7.24.2)
Timeline
- 2026-04-02: disclosed: Claude coding agent alerted to vulnerability
- 2026-05-04: advisory: CVE-2026-42571 published to GitHub Advisory Database
- 2026-04-08: patched: Patches released in v7.21.5, v7.22.3, v7.23.3, v7.24.2