Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 26 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Access Control Bypass via Semicolon Injection in Peplink InControl 2 |
Fri, 26 Jun 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints. | |
| Weaknesses | CWE-551 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-26T13:32:31.453Z
Reserved: 2026-06-26T12:20:51.599Z
Link: CVE-2026-57920
Updated: 2026-06-26T13:32:19.714Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T13:30:16Z