CVE-2024-36542

HIGH

kuma <2.7.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Scores

CVSS v3 8.8
EPSS 0.0009
EPSS Percentile 26.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-277
Status published
Published Jul 25, 2024
Tracked Since Feb 18, 2026