Description
Incorrect Privilege Assignment vulnerability in Modular DS allows Privilege Escalation.This issue affects Modular DS: from n/a through 2.5.1.
Problem types
CWE-266 Incorrect Privilege Assignment
Product status
Any version
Timeline
| 2026-01-13: | Exploitation identified through log analysis |
| 2026-01-14: | Exploitation and vulnerability reported to the Patchstack Threat Intelligence Team |
| 2026-01-14: | Patchstack RapidMitigate virtual patch deployed |
| 2026-01-14: | Vendor notified of the vulnerability and active exploitation |
| 2026-01-14: | Vendor released an official patch |
Credits
Teemu Saarentaus | Patchstack Bug Bounty Program
References
patchstack.com/...ivilege-escalation-vulnerability?_s_id=cve
patchstack.com/...affecting-40k-sites-exploited-in-the-wild/
help.modulards.com/...-release-modular-connector-252-dm3mv0/