CVE-2026-57920
EUVD-2026-3965126.06.2026, 13:16
Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.EnginsightAffected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| peplink | intcontrol_2 | 𝑥 ≤ 2.14.2 |
𝑥
= Vulnerable software versions