A vulnerability described as critical has been identified in rConfig up to 8.2.7. Affected by this vulnerability is an unknown functionality of the component StoreUserRequest. Executing a manipulation of the argument role can lead to improper authorization.

The identification of this vulnerability is CVE-2026-63102. The attack may be launched remotely. There is no exploit available.