A vulnerability, which was classified as critical , has been found in tabaoca.org Cotton Cloud Extension up to 2.0.2 . The affected element is an unknown function of the component ACL Implementation . Performing a manipulation results in improper privilege management. This vulnerability is reported as CVE-2026-67284 . The attack is possible to be carried out remotely. No exploit exists. It is advisable to upgrade the affected component.