An issue in ETSI Open-Source MANO (OSM) v.14.x, v.15.x allows a remote attacker to escalate privileges via the /osm/admin/v1/users component
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.