CVE Feed

    Dashboard / CVE / CVE-2026-32097

    CVE-2026-32097

    PingPong is a platform for using large language models (LLMs) for teaching and learning. Prior to 7.27.2, an authenticated user may be able to retrieve or delete files outside the intended authorization scope. This issue could result in retrieval or deletion of private files, including user-uploaded files and model-generated output files. Exploitation required authentication and permission to view at least one thread for retrieval, and authentication and permission to participate in at least one thread for deletion. This vulnerability is fixed in 7.27.2.

    Published:Mar 11, 2026
    Last Modified:Mar 20, 2026
    EPS:Mar 11, 2026
    EPSS Score:0.00068
    CVSS Score:8.8

    Affected Products

    Vendor
    Comppolicylab
    Product
    Pingpong
    Vendor
    Harvard
    Product
    Pingpong

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High