EIP-2026-102392
PRE-CVELiferay Portal 6.0.x < 6.1 - Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102392. PoCs published by Jelmer Kuperus.
AI-analyzed exploit summary This exploit demonstrates a privilege escalation vulnerability in Liferay Portal due to insufficient permission checks in the `updateOrganizations` method. An attacker can assign themselves to any organization via a crafted HTTP request, potentially gaining elevated privileges.
Description
Liferay Portal 6.0.x < 6.1 - Privilege Escalation
Exploits (1)
This exploit demonstrates a privilege escalation vulnerability in Liferay Portal due to insufficient permission checks in the `updateOrganizations` method. An attacker can assign themselves to any organization via a crafted HTTP request, potentially gaining elevated privileges.