CVE-2026-30269: Doorman

Critical severity, CVSS 9.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role via /platform/user/{username}. The `role` field is accepted by the update model without a manage_users permission check for self-updates, enabling privilege escalation to high-privileged roles.

Affected products

  • Doorman Doorman: version 0.1.0 only; version 1.0.2 only

Published 2026-04-20. Last modified 2026-06-17.