Junglewise Threat Intelligence

CVE-2026-72564: fosrl pangolin improper authorization in access token validation

CVE-2026-72564 · Severity: critical · CVSS 9.6 · Published 2026-08-10

Executive brief

Pangolin is a modern networking and security platform that manages access to applications, infrastructure, and workloads. An authenticated user can reuse access tokens issued for one resource to gain unauthorized access to any resource in any organization, effectively bypassing access controls and allowing lateral movement across the entire system.

Technical details

An improper authorization vulnerability exists in the access token validation logic (authWithAccessToken.ts) where tokens issued for a specific resource are not properly scoped to that resource. An authenticated remote attacker can reuse a valid access token originally issued for a different resource to authenticate to any other resource in any organization. The vulnerability requires initial authentication (token possession) but lacks per-resource token validation, allowing unlimited privilege escalation. No indication of patch availability is provided in the advisory.

Affected products

  • fosrl pangolin through v1.20.0

Timeline

  • 2026-08-10: disclosed

References