Junglewise Threat Intelligence

CVE-2026-50770: Squirro Cognitive Search privilege escalation via access control bypass

CVE-2026-50770 · Severity: critical · CVSS 9.8 · Published 2026-08-17

Technologies: Squirro Cognitive Search. Vendors: Squirro.

Executive brief

Squirro Cognitive Search is an enterprise search platform that helps organizations find information across connected data sources using AI and machine learning. A vulnerability allows low-privilege users to perform administrative actions—such as viewing all users, uploading files, and accessing logs—by sending crafted requests that bypass access controls. This could enable unauthorized users to compromise data confidentiality, modify system configurations, or gain full administrative control.

Technical details

The vulnerability is an improper access control flaw affecting Squirro Cognitive Search versions before 3.14.2. The application fails to properly validate user roles and permissions when processing administrative API requests, allowing a user with low-privilege (User role) to perform actions restricted to the Admin role. The attack requires the attacker to be authenticated to the application; they can then reuse their low-privilege session cookie to access protected endpoints such as /v0/users (to list all users), file upload endpoints, and logging interfaces. By intercepting admin requests and replaying them with low-privilege credentials, attackers can circumvent role-based access controls and escalate privileges. The fix is available in version 3.14.2 and later.

Affected products

  • Squirro Cognitive Search before 3.14.2

Timeline

  • 2026-08-17: disclosed
  • 2026: patched: Fixed in version 3.14.2

References

Related threats