CVE-2026-27012Disclosure(devcode / openstamanager)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch devcode openstamanager systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to arbitrarily change a user's group (idgruppo) by directly calling modules/utenti/actions.php. This can promote an existing account (e.g. agent) into the Amministratori group as well as demote any user including existing administrators.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openstamanager

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-03); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
openstamanager

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-03: 3Mentions · 2026-03-04: 2Patch / Workaround · 2026-03-03: 1Technical Details · 2026-03-03: 3Technical Details · 2026-03-04: 203-0303-04
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-033
Disclosure2Patch1
2026-03-042
Disclosure2
Full discourse5 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27012 Privilege Escalation and Authentication Bypass in OpenSTAManager 2.9.8 and Earlier https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27012

    Post summary

    The text announces a privilege escalation and authentication bypass vulnerability in OpenSTAManager 2.9.8 and earlier, with no mention of PoC, exploit, patch, or active exploitation.

    0001054
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-27012 - Critical OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenST... https://www.thehackerwire.com/vulnerability/CVE-2026-27012/ https://t.co/eetw4jKj3S

    Post summary

    The post announces a privilege escalation and authentication bypass vulnerability in OpenSTAManager 2.9.8 and earlier, providing only basic technical details and no PoC, exploit, or patch information.

    0000038
    121 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27012: CRITICAL] Vulnerability in OpenSTAManager 2.9.8 and earlier allows attackers to escalate privileges. Upgrade to the latest version to patch this security flaw. #cybersecurity#cve,CVE-2026-27012,#cybersecurity https://cvefind.com/CVE-2026-27012

    Post summary

    The post highlights a critical privilege‑escalation flaw in OpenSTAManager and urges users to upgrade to the latest version to mitigate the risk.

    0000045
    593 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27012 OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vu… https://www.cve.org/CVERecord?id=CVE-2026-27012 ----- Traducción: CVE-2026-27012 Ope… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-27012, noting a privilege escalation and authentication bypass in OpenSTAManager versions 2.9.8 and earlier, with no mention of PoC, exploit, patch, or active exploitation.

    0000026
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27012 OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vu… https://www.cve.org/CVERecord?id=CVE-2026-27012

    Post summary

    The post references CVE-2026-27012, noting a privilege escalation and authentication bypass in OpenSTAManager versions 2.9.8 and earlier, but provides no further details or evidence of exploitation.

    00000187
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdevcodeopenstamanager---

Explore more