---
id: CVE-2026-92753
title: >-
  PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in
  the events and alerts API endpoints that lack ownership filtering
summary: >-
  PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in
  the events and alerts API endpoints that lack ownership filtering.
  Authenticated attackers can read platform event history, delete arbitrary
  events, and modif…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'
cwe:
  - CWE-862
vendor: Patrowl
product: PatrowlManager
affected:
  - PatrowlManager <= 1.8.4
published: '2026-09-16'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:49.153'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92753'
references:
  - url: 'https://github.com/Patrowl/PatrowlManager'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Patrowl/PatrowlManager/blob/1.8.4/events/apis.py#L15-L60
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Patrowl/PatrowlManager/issues/474'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/patrowlmanager-through-1.8.4-authorization-bypass-via-events-api
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Patrowl/PatrowlManager/issues/474'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00377
epssPercentile: 0.29086
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T18:26:45.605907Z'
ingestedAt: '2026-09-16T21:05:36.898Z'
---

## Overview

PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modify alerts belonging to other users.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
