Generated remediation guidance and an executive summary. No account required.
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several pages in the Web Console. This enables a view-only user to change any configuration setting and delete any registered agents. All versions before 7.11.1 are affected.
Cite this page
CVE-2021-27900. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2021-27900
Use CWE-862, Proofpoint vendor hub and Insider Threat Management product page to widen CVE-2021-27900 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-8884, CVE-2022-25294 and CVE-2021-22159 for nearby disclosures in the same product family. Additional editorial context is available in Weekly Security Roundup: Navigating the April 2026 Threat Landscape and Critical Framework Exploits.