CVE-2026-19928 | OpenBoxes up to 0.9.7 Role Interceptor RoleInterceptor.groovy needManager privileges management (GHSA-9rrw-fx2p-p2q7)
A vulnerability described as critical has been identified in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a manipulation can lead to improper privilege management.
This vulnerability appears as CVE-2026-19928. The attack may be performed from remote. In addition, an exploit is available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More