CVE-2026-103470: INTERNET2 Grouper
Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.
In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.
Affected products
- INTERNET2 Grouper: from 5.8.3, up to and including 5.22.5; from 6.0.0, before 6.4.1 (fixed in 6.4.1); from 7.0.0, before 7.5.1 (fixed in 7.5.1)
Published 2026-09-30. Last modified 2026-09-30.