CVE-2023-47031
Critical · CVSS 9.8NCR Terminal Handler — Improper Access Control - Privilege Escalation via SOAP API
- CVSS
- 9.8
- nvd
- EPSS
- 0.55%
- 42th pct
- KEV
- No
- Class
- other
- CWE-284
Description
An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOrganization SOAP API component.
Search profile — drives PoC discovery
Symbols grantRolesToUsersgrantRolesToGroupsgrantRolesToOrganization
Keywords CVE-2023-47031NCR Terminal Handlerprivilege escalationSOAP APIgrantRolesToUsersgrantRolesToGroupsgrantRolesToOrganizationNCR PoC exploit
Versions: 1.5.1
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z