Junglewise Threat Intelligence

CVE-2026-57920: Peplink InControl 2 access control bypass in REST API

CVE-2026-57920 · Severity: high · CVSS 7.7 · Published 2026-06-26

Executive brief

Peplink InControl 2, a cloud-based endpoint management system for networking devices, contains a security flaw that allows users to bypass access controls. By using a semicolon in specific web requests, an authenticated user could gain unauthorized access to organizational data they are not permitted to see. This could lead to the exposure of sensitive configuration or operational information across different customer organizations.

Technical details

A path normalization or authorization-order vulnerability (CWE-551) exists in Peplink InControl 2. The application fails to correctly parse or canonicalize URLs containing semicolons before performing authorization checks on REST API endpoints under /rest/o/{orgId}. An authenticated attacker can exploit this by injecting a semicolon into the request path to bypass access-control filters, potentially accessing data belonging to other organizations. The issue is resolved in versions released on or after June 3, 2026.

Affected products

  • Peplink InControl 2 Through 2.14.2 before 2026-06-03

Timeline

  • 2026-06-03: patched: Fix implemented in production/release
  • 2026-06-26: disclosed: CVE published

References