๐Ÿ” CVE Alert

CVE-2026-42571

UNKNOWN 0.0

Privilege Escalation Attack affecting Pelican Web UI

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
11th

Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.24.0 to before 7.24.2, there is a a privilege escalation vulnerability affecting Pelican's Web User Interface (WebUI). This attack allows any user authenticated to the WebUI via OAuth to gain admin privileges under certain configurations. This issue has been patched in versions 7.21.5, 7.22.3, 7.23.3, and 7.24.2.

CWE CWE-863
Vendor pelicanplatform
Product pelican
Published May 9, 2026
Last Updated May 12, 2026
Stay Ahead of the Next One

Get instant alerts for pelicanplatform pelican

Be the first to know when new unknown vulnerabilities affecting pelicanplatform pelican are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

PelicanPlatform / pelican
>= 7.21.0, < 7.21.5 >= 7.22.0, < 7.22.3 >= 7.23.0, < 7.23.3 >= 7.24.0, < 7.24.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/PelicanPlatform/pelican/security/advisories/GHSA-rpfr-x88x-xwcw github.com: https://github.com/PelicanPlatform/pelican/commit/7f73b9c3e677a0ae4a0ec465c5d98bb8bd948854