CVE-2026-103470
Received Received - Intake

Privilege Escalation in Internet2 Grouper

Vulnerability report for CVE-2026-103470, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: MITRE

Description

In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
internet2 grouper From 5.8.3 (inc) to 7.5.1 (exc)
internet2 grouper From 6.0.0 (inc) to 6.4.1 (exc)
internet2 grouper 7.5.1
internet2 grouper 6.4.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-103470 is a privilege escalation vulnerability in Internet2 Grouper's User Interface rules feature. It allows authenticated users with specific admin privileges to escalate their access rights beyond intended levels.

Detection Guidance

To detect this vulnerability, check for unauthorized rule creation in the Grouper UI. Review the rules.restrictRulesUiToMembersOfThisGroupName property in grouper.properties to see if it is misconfigured. Use the GSH report provided in the patch notes to audit existing rules for any suspicious activity.

Impact Analysis

An attacker with ADMIN on a group or STEM_ADMIN on a folder could gain higher privileges, potentially allowing unauthorized access to sensitive data or system functions. This requires the attacker to be authenticated and meet specific configuration conditions.

Mitigation Strategies

Immediately restrict rule creation in the UI to system administrators by setting rules.restrictRulesUiToMembersOfThisGroupName to the wheel group in grouper.properties. Audit existing rules using the GSH report to identify and remove unauthorized rules. Upgrade to Grouper v7.5.1 or v6.4.1 as soon as possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103470. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart