CVE-2026-57920
EUVD-2026-3965126.06.2026, 13:16
Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.EnginsightAwaiting analysis
This vulnerability is currently awaiting analysis.