CVE-2026-57920: Peplink InControl 2 Access Control Bypass via Semicolon Injection
Peplink InControl 2 is vulnerable to an access-control bypass affecting REST API endpoints. An authenticated attacker can inject a semicolon character into requests to certain `/rest/o/{orgId}` endpoints to circumvent access-control rules and read sensitive organizational data. The vulnerability exists in versions through 2.14.2 and was patched on June 3, 2026. Because exploitation requires a valid login and does not enable data modification or system disruption, the risk is containable but significant for organizations managing multi-tenant deployments.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.7 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- Weaknesses (CWE)
- CWE-551
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-26 / 2026-07-02
NVD description (verbatim)
Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-57920 is a path traversal variant classified as Insufficient Access Control (CWE-551). When an authenticated user crafts a request to a REST endpoint under `/rest/o/{orgId}` and includes a semicolon in the request path, the application's access-control logic fails to properly validate the intended organization context. This allows the attacker to read data or perform reconnaissance on organizations they should not have access to. The vulnerability was introduced in InControl 2 and persists through version 2.14.2; fixes were integrated after June 3, 2026.
Business impact
Organizations operating Peplink InControl 2 as a centralized management platform for branch connectivity and SD-WAN deployments face data exposure risk across multiple organizational tenants. An insider with basic user credentials—help desk staff, junior network engineers, managed service provider technicians—could enumerate and access customer or sibling organization configurations, including network topology, security policies, and operational settings. In multi-tenant MSP environments, this creates direct liability and trust erosion with clients. The impact is primarily confidentiality; integrity and availability of the control plane remain intact.
Affected systems
Peplink InControl 2 versions up to and including 2.14.2 are affected. Organizations must verify their installed version by checking the InControl 2 administration console. Patch status depends on whether the instance has been updated after June 3, 2026, or whether a subsequent patch release (post-2.14.2) has been deployed. Confirm against the Peplink security advisory for the exact version boundary and any interim patched builds.
Exploitability
Exploitation requires valid InControl 2 credentials and network access to the management console API. An attacker cannot exploit this anonymously; compromise of any user account (support staff, partner, internal network access) becomes a pivot point. The actual exploit is straightforward—injecting a semicolon into a URL path—meaning that once credentials are obtained, execution is low-friction. No special tools or advanced techniques are needed. The CVSS score of 7.7 (HIGH) reflects this combination: network-accessible, low complexity, but requiring prior authentication and limited to information disclosure.
Remediation
Upgrade InControl 2 to a patched release confirmed to be dated after June 3, 2026. Verify with your Peplink account team or security advisory that the target version includes the fix for CVE-2026-57920. Additionally, implement network segmentation to restrict API access to trusted administrative networks, enforce strong password policies and multi-factor authentication for console accounts, and audit access logs for suspicious REST API calls with unusual path patterns.
Patch guidance
Peplink has released patches post-2.14.2; consult the official Peplink security bulletin for the specific version number. Plan maintenance during a change window and test the upgrade in a staging environment first, as InControl 2 upgrades may affect active managed devices. Vendors often provide zero-downtime or scheduled-maintenance options; coordinate with your support team. After patching, verify the fix by confirming the new version number in the console and reviewing recent API access logs for any unauthorized cross-organization queries.
Detection guidance
Monitor InControl 2 API logs for requests to `/rest/o/{orgId}` endpoints containing semicolon characters in the path or query parameters. Alert on successful 200 responses from users accessing organization IDs outside their assigned scope. SIEM integration with InControl 2 audit logs can flag anomalous REST API patterns. Additionally, review user access logs to identify any low-privilege accounts making administrative API calls or cross-organization data retrieval attempts in the weeks before patching.
Why prioritize this
Although this vulnerability requires authentication and is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, it carries meaningful risk in shared-infrastructure environments. Multi-tenant MSP deployments, partner networks, and large enterprises with federated organization structures should prioritize patching. The ease of exploitation once credentials are compromised, combined with direct exposure of operational and security configurations, justifies treating this as a high-priority patching task in the next scheduled change window.
Risk score, explained
The CVSS 3.1 score of 7.7 reflects a HIGH severity rating. The vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N indicates: network-accessible without physical proximity, low complexity to exploit (simple injection), requires low-privilege authenticated user, no user interaction needed, and impacts the confidentiality of resources beyond the vulnerable scope (cross-tenant data). The lack of integrity or availability impact keeps the score from reaching critical, but the broad scope and high confidentiality impact justify the HIGH rating.
Frequently asked questions
Can this vulnerability be exploited without a valid user account?
No. The vulnerability requires authentication to the InControl 2 console. An attacker must first obtain valid credentials for any user account, even a low-privilege one, before attempting to bypass access controls.
Does patching require a service restart or downtime?
Consult the Peplink upgrade guide for your specific version. Many InControl 2 patches support staged or zero-downtime updates, but this depends on your deployment. Always test in a staging environment and plan a maintenance window to ensure managed devices are not disrupted.
How can I tell if my InControl 2 instance has been exploited?
Review the REST API access logs in the InControl 2 audit trail for requests to `/rest/o/{orgId}` endpoints from unexpected users or containing unusual path patterns. Look for 200 OK responses for organization IDs outside the user's normal scope of responsibility.
Is this vulnerability listed as actively exploited in the wild?
As of the publication date, this vulnerability is not on CISA's Known Exploited Vulnerabilities (KEV) catalog, meaning there is no confirmed evidence of active exploitation in the wild. However, the straightforward nature of the attack and the value of InControl 2 data means it remains a credible insider risk.
This analysis is provided for informational purposes and reflects the vulnerability details and patch status as of the publication date. Security patch availability, version numbers, and remediation timelines should be verified against the official Peplink security advisory and your vendor support channels. Organizations should test all patches in a non-production environment before deployment. SEC.co does not provide warranty or guarantee regarding the completeness or currency of this intelligence and recommends consulting Peplink and your security team for organization-specific risk assessment and compliance obligations. Source: NVD (public-domain), retrieved 2026-08-05. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-13676HIGHfast-uri IDN Canonicalization Bypass – Host Policy Enforcement Risk
- CVE-2026-45832HIGHChromaDB Authorization Bypass via V1 Endpoints
- CVE-2026-50559HIGHQuarkus HTTP Authorization Bypass via Encoded Characters
- CVE-2016-20062HIGHSQL Injection in Simply Poll 1.4.1 WordPress Plugin - Unauthenticated Data Theft
- CVE-2016-20063HIGHSQL Injection in Single Personal Message 1.0.3 – Credential & Data Theft Risk
- CVE-2016-20065HIGHUnauthenticated SQL Injection in Product Catalog 8 WordPress Plugin
- CVE-2016-20066HIGHWordPress CP Polls 1.0.8 Persistent XSS Vulnerability
- CVE-2016-20068HIGHUnauthenticated SQL Injection in WordPress Booking Calendar Contact Form 1.0.23