CVE-2026-1978

A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the file /data/pagesdata.txt of the component User Information Handler. Performing a manipulation results in direct request. It is possible to initiate the attack remotely. The exploit is now public and may be used. You should change the configuration settings.
References
Link Resource
https://github.com/kalyan02/NanoCMS/ Product
https://github.com/kalyan02/NanoCMS/blob/master/data/pagesdata.txt Product
https://vuldb.com/?ctiid.344500 Permissions Required VDB Entry
https://vuldb.com/?id.344500 Third Party Advisory VDB Entry
https://vuldb.com/?submit.743260 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:kalyan02:nanocms:*:*:*:*:*:*:*:*

History

27 Feb 2026, 20:10

Type Values Removed Values Added
References () https://github.com/kalyan02/NanoCMS/ - () https://github.com/kalyan02/NanoCMS/ - Product
References () https://github.com/kalyan02/NanoCMS/blob/master/data/pagesdata.txt - () https://github.com/kalyan02/NanoCMS/blob/master/data/pagesdata.txt - Product
References () https://vuldb.com/?ctiid.344500 - () https://vuldb.com/?ctiid.344500 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.344500 - () https://vuldb.com/?id.344500 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.743260 - () https://vuldb.com/?submit.743260 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:kalyan02:nanocms:*:*:*:*:*:*:*:*
First Time Kalyan02
Kalyan02 nanocms
Summary
  • (es) Una vulnerabilidad fue detectada en kalyan02 NanoCMS hasta 0.4. Afectada por este problema es alguna funcionalidad desconocida del archivo /data/pagesdata.txt del componente User Information Handler. Realizar una manipulación resulta en solicitud directa. Es posible iniciar el ataque remotamente. El exploit es ahora público y puede ser usado. Debería cambiar la configuración.

06 Feb 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-06 05:16

Updated : 2026-02-27 20:10


NVD link : CVE-2026-1978

Mitre link : CVE-2026-1978

CVE.ORG link : CVE-2026-1978


JSON object : View

Products Affected

kalyan02

  • nanocms
CWE
CWE-425

Direct Request ('Forced Browsing')