← Vulnerability feed

Vulnerability record · CVE-2021-42562 · published 12 January 2022

CVE-2021-42562: Mitre caldera improper privilege management vulnerability

Mitre · Caldera

An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modify configuration or other components that should only be accessible by admin users.

8.1 CVSS 3.1 High EPSS 1.2% · top 33.3% CWE-269 · Improper privilege management
8.1CVSS 3.1 base score, v2 5.5
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modify configuration or other components that should only be accessible by admin users.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-42562 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-42559Mitre caldera command injection vulnerabilityAn issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these c…EPSS 2.0%8.8CVE-2021-42560Mitre caldera xml external entity (xxe) vulnerabilityAn issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG docum…EPSS 2.1%8.8CVE-2021-42561Mitre caldera injection vulnerabilityAn issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. Th…EPSS 20%8.8CVE-2020-19907Mitre caldera os command injection vulnerabilityA command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.EPSS 3.0%6.1CVE-2022-40606Mitre caldera cross-site scripting vulnerabilityMITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-20…EPSS 0.46%6.1CVE-2022-40605Mitre caldera cross-site scripting vulnerabilityMITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-20…EPSS 0.46%6.1CVE-2021-42558Mitre caldera cross-site scripting vulnerabilityAn issue was discovered in CALDERA 2.8.1. It contains multiple reflected, stored, and self XSS vulnerabilities that may be exploited by authenticated…EPSS 1.1%5.4CVE-2022-41139Mitre caldera cross-site scripting vulnerabilityMITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on …EPSS 0.57%

Source: NIST National Vulnerability Database (record CVE-2021-42562), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.