Junglewise Threat Intelligence

CVE-2026-44987: Syslifters SysReptor privilege escalation in user management

CVE-2026-44987 · Severity: low · CVSS 3.8 · Published 2026-05-08

Technologies: Syslifters SysReptor. Vendors: Syslifters.

Executive brief

SysReptor is a platform used by security teams to create and manage penetration testing reports. A vulnerability allows users with administrative access to change the email addresses of high-level 'Superusers,' potentially leading to full account takeover if password reset features are enabled. This could allow an attacker to access sensitive security findings across all projects or modify global system settings.

Technical details

An improper privilege management vulnerability (CWE-269) exists in SysReptor's user management component. Users with 'User Admin' privileges can modify the email addresses associated with 'Superuser' accounts. If the optional 'Forgot Password' feature is enabled and the target Superuser does not have Multi-Factor Authentication (MFA) active, the User Admin can trigger a password reset to an email address they control. This grants the attacker access to the Django administration backend and the ability to escalate their own permissions to 'Project Admin' across all pentest projects. The issue is resolved in version 2026.29.

Affected products

  • Syslifters sysreptor < 2026.29

Timeline

  • 2026-05-06: patched: Issue patched in version 2026.29
  • 2026-05-08: disclosed: Public advisory published

References

Related threats