Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 10 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Suitenumerique
Suitenumerique people |
|
| Vendors & Products |
Suitenumerique
Suitenumerique people |
Fri, 08 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0, a user holding the Administrator role on a mail domain could send a crafted invitation request to promote any existing user (including users with no current domain access) to the Owner role. The exploit requires a single authenticated HTTP request and grants full domain ownership immediately, without any acceptance step from the target. This issue has been patched in version 1.25.0. | |
| Title | People: Privilege Escalation via Missing Role Ceiling in Mail Domain Invitation | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-08T19:53:16.358Z
Reserved: 2026-04-25T01:53:21.583Z
Link: CVE-2026-42185
Updated: 2026-05-08T19:53:11.320Z
Status : Deferred
Published: 2026-05-08T20:16:31.290
Modified: 2026-05-13T16:34:42.677
Link: CVE-2026-42185
No data.
OpenCVE Enrichment
Updated: 2026-05-10T21:24:54Z