CVE-2023-36646: Prolion Cryptospike
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute privileged functions and achieve privilege escalation via REST API endpoint invocation.
Affected products
- Prolion Cryptospike: version 3.0.15 only
Published 2023-12-12. Last modified 2026-06-17.