Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.24.0 to before 7.24.2, there is a a privilege escalation vulnerability affecting Pelican's Web User Interface (WebUI). This attack allows any user authenticated to the WebUI via OAuth to gain admin privileges under certain configurations. This issue has been patched in versions 7.21.5, 7.22.3, 7.23.3, and 7.24.2.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rpfr-x88x-xwcw | Pelican Web UI Affected by a Privilege Escalation Attack |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 10 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pelicanplatform
Pelicanplatform pelican |
|
| Vendors & Products |
Pelicanplatform
Pelicanplatform pelican |
Sat, 09 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.24.0 to before 7.24.2, there is a a privilege escalation vulnerability affecting Pelican's Web User Interface (WebUI). This attack allows any user authenticated to the WebUI via OAuth to gain admin privileges under certain configurations. This issue has been patched in versions 7.21.5, 7.22.3, 7.23.3, and 7.24.2. | |
| Title | Privilege Escalation Attack affecting Pelican Web UI | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-09T19:19:36.522Z
Reserved: 2026-04-28T17:26:12.084Z
Link: CVE-2026-42571
No data.
Status : Received
Published: 2026-05-09T20:16:29.277
Modified: 2026-05-09T20:16:29.277
Link: CVE-2026-42571
No data.
OpenCVE Enrichment
Updated: 2026-05-10T21:24:26Z
Weaknesses
Github GHSA