Feed/CVE-2026-42571
CVE-2026-42571CRITICALCVSS 0.0

CVE-2026-42571

Published May 9, 2026·Updated Aug 19, 2026

NVD Description

Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.24.0 to before 7.24.2, there is a a privilege escalation vulnerability affecting Pelican's Web User Interface (WebUI). This attack allows any user authenticated to the WebUI via OAuth to gain admin privileges under certain configurations. This issue has been patched in versions 7.21.5, 7.22.3, 7.23.3, and 7.24.2.

Affected Packages (1)

github.com/pelicanplatform/pelicanGO
Fixed in 0.0.0-20260408120501-7f73b9c3e677

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free