
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27012 is a critical unauthenticated privilege escalation and authentication bypass vulnerability in OpenSTAManager, an open source management software for technical assistance and invoicing. It affects all versions up to and including 2.9.8, and was published on March 3, 2026 via a GitHub Security Advisory. The vulnerability allows any unauthenticated attacker to arbitrarily change a user's group assignment (idgruppo) by directly calling modules/utenti/actions.php, enabling promotion of any account to administrator or demotion of existing administrators. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, OSM Security Advisory).
The root cause is classified as CWE-306 (Missing Authentication for Critical Function). The file modules/utenti/actions.php is directly accessible over HTTP (e.g., http://<host>:8080/modules/utenti/actions.php) and explicitly sets $skip_permissions = true; before including core.php, which in turn calls Permissions::skip() — effectively disabling all authentication and authorization enforcement. An attacker can send a crafted unauthenticated HTTP POST request with an op parameter (e.g., update_user) and supply arbitrary values for sensitive fields such as idgruppo (group ID), causing the application to update the target user's database record without any credential or session validation. No prior account or special network position is required; the endpoint is exploitable by any network-reachable attacker (OSM Security Advisory, GitHub Advisory).
Successful exploitation allows a fully unauthenticated attacker to assign administrator privileges to any existing user account, demote or lock out legitimate administrators, and modify or disable arbitrary accounts. This results in complete application compromise with high impact to confidentiality (access to all application data including invoicing and customer records), integrity (unrestricted modification of user and business data), and availability (ability to disable administrator accounts or disrupt operations). The vulnerability can also be used to enable/disable accounts and perform other privileged operations exposed through the affected file (OSM Security Advisory, GitHub Advisory).
A proof-of-concept (PoC) exploit is publicly available in the GitHub Security Advisory, demonstrating exploitation via a simple crafted POST request using tools such as Burp Suite — no authentication or cookies are required. As of the time of disclosure, there is no confirmed evidence of active in-the-wild exploitation, and no threat actor attribution has been reported (OSM Security Advisory). The EPSS score is approximately 0.046% (15th percentile), indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (GitHub Advisory).
id=4) that exists in the system.http://<host>:8080/modules/utenti/actions.php with parameters including op=update_user, the target user's id, and idgruppo=<admin_group_id> (the ID corresponding to the "Amministratori" group)./modules/utenti/actions.php from external or unusual IP addresses, particularly with parameters including op=update_user and idgruppo.modules/utenti/actions.php without associated session cookies or authentication tokens; repeated requests from the same IP targeting this endpoint.an_utenti (or equivalent users) table showing idgruppo field changes not initiated by a legitimate administrator session, especially at unusual times.As of the advisory publication date (March 3, 2026), no patched version of OpenSTAManager has been released — the advisory lists "None" for patched versions, and all versions up to and including 2.9.8 are affected (GitHub Advisory). Immediate recommended mitigations include: implementing network-level access controls (firewall rules or web server configuration) to block unauthenticated external access to modules/utenti/actions.php; restricting OpenSTAManager to trusted internal networks only; auditing all user group assignments and administrator accounts for unauthorized changes; and monitoring web server logs for suspicious POST requests to the affected endpoint. Organizations should monitor the OSM Security Advisory for patch availability and upgrade as soon as a fixed version is released.
The vulnerability received coverage from The Hacker Wire, which published an article on the critical privilege escalation and authentication bypass (The Hacker Wire). Social media discussion was noted on Mastodon and Bluesky shortly after disclosure. The vulnerability was also picked up by automated CVE tracking feeds and vulnerability aggregators including Vulners, CVEFeed, and CIRCL's vulnerability database within hours of publication.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."