CVE-2026-42571

CRITICAL

Privilege Escalation Attack affecting Pelican Web UI

Title source: cna
STIX 2.1

Description

Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.24.0 to before 7.24.2, there is a a privilege escalation vulnerability affecting Pelican's Web User Interface (WebUI). This attack allows any user authenticated to the WebUI via OAuth to gain admin privileges under certain configurations. This issue has been patched in versions 7.21.5, 7.22.3, 7.23.3, and 7.24.2.

Scores

CVSS v4 9.0
EPSS 0.0032
EPSS Percentile 23.5%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-863
Status published
Products (5)
pelicanplatform/pelican 0 - 0.0.0-20260408120501-7f73b9c3e677Go
PelicanPlatform/pelican >= 7.21.0, < 7.21.5
PelicanPlatform/pelican >= 7.22.0, < 7.22.3
PelicanPlatform/pelican >= 7.23.0, < 7.23.3
PelicanPlatform/pelican >= 7.24.0, < 7.24.2
Published May 09, 2026
Tracked Since May 10, 2026