Galette Group Manager Role-Based Access Control Bypass Vulnerability

Vulnerability

A vulnerability in Galette, a membership management web application for non-profit organizations, allows group managers to bypass role-based access controls. This issue is present in Galette versions 0.9.6 through 1.2.0. Exploitation of this vulnerability enables unauthorized access and modifications, despite existing role restrictions. The flaw arises from an access control oversight that affects group managers, whether malicious insiders or those with compromised accounts.

Impact

Exploitation of this vulnerability could lead to unauthorized access and changes within the application, allowing group managers to manipulate member data or permissions contrary to established role guidelines.

Reproduction

To reproduce this vulnerability, first ensure that the 'Can group managers create members?' option is disabled and the 'Can members create child' option is enabled in the Galette settings. Then, sign in as a group manager and access the 'addMember' GET route. The route will be accessible, despite it being disabled in the current settings.

Remediation

Users can upgrade to Galette version 1.2.0 or later to address this vulnerability.

Added: Dec 19, 2025, 5:33 PM
Updated: Dec 19, 2025, 6:06 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
5.0
exploitability
6.6
remediation
7.7
relevance
1.4
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.