Executive brief
A security flaw in the Augmentt web application allows regular users to gain full administrative control. By manipulating data sent between their browser and the server, a standard user can bypass security checks to access sensitive information and modify system data. This could lead to a total compromise of the platform's data and management functions.
Technical details
A privilege escalation vulnerability exists in the Augmentt web application due to insufficient granularity of access control (CWE-1220). The application relies on client-side parameters to determine user permissions rather than enforcing them strictly on the server side. An authenticated attacker with standard user privileges can intercept and modify HTTP response parameters (specifically within the 'Support' menu under 'Management') to elevate their privileges to super administrator. This allows the attacker to bypass intended access restrictions, view sensitive administrative data, and perform unauthorized data modifications. As of the advisory date, the vendor has not responded to disclosure attempts, though mitigation involves implementing server-side role verification.
Affected products
- Augmentt Augmentt Web Application Versions prior to 2025-10-02
Timeline
- 2025-10-02: disclosed: Initial report sent to vendor
- 2026-04-16: other: CVE assigned
- 2026-04-22: advisory: NVD publication date