logo

Avo Flaw CVE-2026-55518 Enables Privilege Escalation in Rails Apps

ID: dd09cbec-d4f1-5a30-84f9-18c12ad2a176

STIX ID: report--dd09cbec-d4f1-5a30-84f9-18c12ad2a176

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Do Son

...
...

Avo HQ released a patch for CVE-2026-55518, a critical (CVSS 9.6) authorization bypass in the Avo admin panel framework for Ruby on Rails that allows authenticated low-privileged users to bypass attach authorization by sending crafted POST requests to association endpoints, potentially enabling privilege escalation and cross-tenant data exposure; affected versions are ≤3.32.0 and 4.0.0-beta.1 through 4.0.0-beta.50, fixed in 3.32.1 and 4.0.0-beta.51 — upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.