---
id: CVE-2026-57920
title: >-
  Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon
  to bypass access-control rules for certain /rest/o/{orgId} endpoints.
summary: >-
  Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon
  to bypass access-control rules for certain /rest/o/{orgId} endpoints.
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-551
vendor: peplink
product: intcontrol_2
affected:
  - intcontrol_2 <= 2.14.2
published: '2026-06-26'
updated: '2026-07-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-57920'
references:
  - url: 'https://drive.google.com/file/d/1MoZn73YkDGGpqOgaQbRU1hWVygr8VaxY/view'
    label: cve@mitre.org
  - url: 'https://drive.google.com/file/d/1MoZn73YkDGGpqOgaQbRU1hWVygr8VaxY/view'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00377
epssPercentile: 0.28988
ingestedAt: '2026-07-03T13:02:28.079Z'
---

## Overview

Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.

## Affected

- `intcontrol_2 <= 2.14.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
