PatrowlManager vulnerabilities
CVEs whose affected-version data names the PatrowlManager package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-92753High· 7.1PoCPatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering
PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modif…
▾ MidnightPatrowl · PatrowlManagerEPSS 0.27%via NVD
CVE-2026-92754Medium· 4.3PoCPatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out
PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can enumerate all use…
▾ TwilightPatrowl · PatrowlManagerEPSS 0.25%via NVD