CVE-2026-103470: INTERNET2 Grouper

Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.

In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.

Affected products

  • INTERNET2 Grouper: from 5.8.3, up to and including 5.22.5; from 6.0.0, before 6.4.1 (fixed in 6.4.1); from 7.0.0, before 7.5.1 (fixed in 7.5.1)

Published 2026-09-30. Last modified 2026-09-30.