---
id: CVE-2026-103470
title: >-
  In Internet2 Grouper before 7.5.1 (in some configurations), a user who is
  allowed to create or edit rules in the User Interface can escalate privileges.
summary: >-
  In Internet2 Grouper before 7.5.1 (in some configurations), a user who is
  allowed to create or edit rules in the User Interface can escalate privileges.
severity: critical
cvss: 9.3
cvssVector: >-
  CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:N/R:U/RE:L/U:Red
cwe:
  - CWE-266
vendor: Internet2
product: Grouper
affected:
  - Grouper >= 5.8.3 <= 5.22.5
  - Grouper >= 6.0.0 < 6.4.1
  - Grouper >= 7.0.0 < 7.5.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T19:16:40.507'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103470'
references:
  - url: 'https://docs.grouper.internet2.edu/wiki/spaces/Grouper/pages/240549893/'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-30T18:42:05.790453Z'
cvssSource: cna
ingestedAt: '2026-09-30T16:10:07.328Z'
---

## Overview

In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
