VDB

CVE-2020-36969

CVE-2020-36969 PUBLISHED CVSS 8.699999809265137 HIGH

M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin parameter. Attackers can send a POST request to the /api/1/admin/users/update endpoint with a crafted payload to grant administrative access to a standard user account.

EPSS 0.49% · 39.7th percentile

Risk Scores

CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.49%
39.7th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10monit1:5.35.2-1, 1:5.34.3-1, 0
Ubuntu:Pro:22.04:LTSmonit*, 1:5.31.0-1ubuntu0.1~esm1, 1:5.30.0-1
Ubuntu:Pro:20.04:LTSmonit*, 0, 1:5.26.0-2
Ubuntu:24.04:LTSmonit1:5.33.0-1, 1:5.33.0-2, 1:5.33.0-2build1
Ubuntu:Pro:18.04:LTSmonit1:5.23.0-2, 1:5.25.1-1, 1:5.23.0-4
Ubuntu:Pro:14.04:LTSmonit1:5.6-2ubuntu0.1+esm2, 1:5.6-2, 1:5.6-1
Ubuntu:Pro:16.04:LTSmonit1:5.16-2ubuntu0.2, 1:5.16-2ubuntu0.2+esm2, 1:5.15-2

Timeline

  • Jan 28, 2026 CVE Published
  • Jan 28, 2026 PoC Published
  • Jan 29, 2026 EPSS Score
  • Feb 1, 2026 EPSS Score
  • Feb 4, 2026 EPSS Score
  • Feb 7, 2026 EPSS Score
  • Feb 10, 2026 EPSS Score
  • Feb 13, 2026 EPSS Score
  • Feb 16, 2026 EPSS Score
  • Feb 19, 2026 EPSS Score
  • Feb 22, 2026 EPSS Score
  • Feb 25, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›