CVE-2026-63085
HIGHAxelor Open Platform 8.x < 8.2.2 Authorization Bypass via Nested Relational Record Persistence
Title source: cnaDescription
Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticated non-admin users to escalate privileges by exploiting unenforced field restrictions on nested relational save operations. Attackers can modify sensitive User record fields such as roles and group by submitting changes through a related entity's save path, bypassing the USER_RESTRICTED_FIELDS control and causing the JPA persistence layer to flush attacker-supplied admin role and group assignments on commit.
References (3)
Core 3
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/geo-chen/oss/blob/main/axelor-open-platform.md
Release Notes release-notes
Release Notes
https://github.com/axelor/axelor-open-platform/releases/tag/v8.2.2
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/axelor-open-platform-8-x-authorization-bypass-via-nested-relational-record-persistence
Scores
CVSS v3
8.8
EPSS
0.0037
EPSS Percentile
29.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-863
Status
published
Products (1)
axelor/axelor-open-platform
8.0.0 - 8.2.2
Published
Jul 16, 2026
Tracked Since
Jul 16, 2026