Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-38470

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 GazellePW(GazellePosterWall)的 commit 86c4bedf727691b5a97af42a4864869d18446449 中,API 用户端点存在一个访问控制缺陷漏洞。该漏洞允许未经特权的已认证用户通过正常使用用户创建的 API 令牌,结合 或 操作,启用或禁用任意用户账户。

AI Predicted 8.1 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1136 · Create Account
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-38470

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A Broken access control vulnerability in the API user endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows unprivileged, authenticated users to enable or disable arbitrary user accounts via the req=disable or req=enable action using a normal user-created API token.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-38470

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-38470

登录查看更多情报信息。

Patches & Fixes for CVE-2026-38470 (1)

Exploits & Public PoCs for CVE-2026-38470 (1)

Proof of Concept for CVE-2026-38470 (1)

Other References for CVE-2026-38470 (1)

Same Patch Batch · n/a · 2026-08-25 · 15 CVEs total

CVE-2026-75465 Maccms v10越权漏洞:敏感信息泄露
CVE-2026-75421 aria2<=1.37.0 IOFile::getLine函数栈缓冲区下溢漏洞
CVE-2026-52489 gpac缓冲区溢出漏洞
CVE-2026-52491 libtiff远程代码执行漏洞
CVE-2026-38467 GazellePW标签管理器存在SQL注入漏洞
CVE-2026-38468 GazellePW 任意代码执行漏洞
CVE-2026-51368 TongWeb v.7.0.24代码执行漏洞
CVE-2026-39113 SQLite < 2026-03-11 快照存在缓冲区溢出致DoS漏洞
CVE-2026-38466 GazellePW存储型XSS漏洞
CVE-2026-38465 GazellePW存储型XSS漏洞
CVE-2026-38469 GazellePW存储型XSS漏洞
CVE-2026-38474 GazellePW IP锁管理器存在越权漏洞
CVE-2026-38473 GazellePW存储型XSS漏洞
CVE-2026-38472 GazellePW存储型XSS漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-38470

No comments yet


Leave a comment