DEBIAN-CVE-2026-56115

Source
https://security-tracker.debian.org/tracker/CVE-2026-56115
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-56115.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-56115
Upstream
Withdrawn
2026-06-26T08:01:37Z
Published
2026-06-23T17:17:09Z
Modified
2026-06-26T08:01:37Z
Severity
  • 6.0 (Medium) CVSS_V4 - CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to perform administrative actions by exploiting missing role enforcement in the JWTMiddleware function in internal/auth/auth.go, which validates JWT tokens and account status but fails to inspect the is_admin flag. Attackers can send requests to any endpoint under the /api/users path to create new administrator accounts or reset administrator passwords, thereby gaining full control of the server and the ability to modify boot menus and installation scripts served to PXE clients.

References

Affected packages

Debian:13 / dhcpcd

Package

Name
dhcpcd
Purl
pkg:deb/debian/dhcpcd?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1:10.*
1:10.1.0-11
1:10.1.0-11+deb13u1
1:10.1.0-11+deb13u2
1:10.1.0-12
1:10.2.0-1
1:10.2.2-1
1:10.2.2-2
1:10.2.2-3
1:10.2.2-4
1:10.2.2-5
1:10.2.2-6
1:10.2.3-1
1:10.2.4-1
1:10.2.4-2
1:10.2.4-3
1:10.2.4-4~bpo13+1
1:10.2.4-4
1:10.3.0-1
1:10.3.0-2~bpo13+1
1:10.3.0-2
1:10.3.0-3~bpo13+1
1:10.3.0-3
1:10.3.0-4
1:10.3.0-5
1:10.3.0-6
1:10.3.0-7~bpo13+1
1:10.3.0-7
1:10.3.1-1~bpo13+1
1:10.3.1-1
1:10.3.1-2
1:10.3.1-3
1:10.3.1-4
1:10.3.1-5~bpo13+1
1:10.3.1-5
1:10.3.2-1
1:10.3.2-2
1:10.3.2-3~bpo13+1
1:10.3.2-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-56115.json"

Debian:14 / dhcpcd

Package

Name
dhcpcd
Purl
pkg:deb/debian/dhcpcd?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1:10.*
1:10.1.0-11
1:10.1.0-12
1:10.2.0-1
1:10.2.2-1
1:10.2.2-2
1:10.2.2-3
1:10.2.2-4
1:10.2.2-5
1:10.2.2-6
1:10.2.3-1
1:10.2.4-1
1:10.2.4-2
1:10.2.4-3
1:10.2.4-4~bpo13+1
1:10.2.4-4
1:10.3.0-1
1:10.3.0-2~bpo13+1
1:10.3.0-2
1:10.3.0-3~bpo13+1
1:10.3.0-3
1:10.3.0-4
1:10.3.0-5
1:10.3.0-6
1:10.3.0-7~bpo13+1
1:10.3.0-7
1:10.3.1-1~bpo13+1
1:10.3.1-1
1:10.3.1-2
1:10.3.1-3
1:10.3.1-4
1:10.3.1-5~bpo13+1
1:10.3.1-5
1:10.3.2-1
1:10.3.2-2
1:10.3.2-3~bpo13+1
1:10.3.2-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-56115.json"