CVE-2026-20773

A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissions.

  • Published Sep 14, 2026
  • CVSS 8.5 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-20773 at the National Vulnerability Database