Junglewise Threat Intelligence

CVE-2026-5781: MphRx Minerva privilege escalation in moUser update endpoint

CVE-2026-5781 · Severity: high · CVSS 8.8 · Published 2026-04-28

Executive brief

MphRx Minerva, a health data platform, contains a security flaw that allows certain users to upgrade their own account permissions. An attacker with basic user-modification rights can bypass standard security controls to grant themselves full administrator access. This could lead to unauthorized access to sensitive medical data and complete control over the platform's operations.

Technical details

An improper authorization vulnerability (CWE-285) exists in the '/minerva/moUser/update' endpoint of MphRx Minerva V3.6.0. The flaw is triggered when an authenticated user with existing user-modification privileges submits a specially crafted HTTP request containing a manipulated 'identifier' field. Because the application fails to properly validate the authorization level associated with this identifier during the update process, a low-privileged user can escalate their role to administrator. Notably, this exploit cannot be performed through the standard graphical user interface and requires direct manipulation of network requests. As of the advisory date, no official patch has been reported.

Affected products

  • MphRx Minerva 3.6.0

Timeline

  • 2026-04-28: advisory: Initial disclosure by INCIBE-CERT
  • 2026-04-28: disclosed: Vulnerability published to NVD

References