CVE-2026-32300

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Versions 1.41.1 and 2.41.1 contain a patch.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:opensource-workshop:connect-cms:*:*:*:*:*:*:*:*
cpe:2.3:a:opensource-workshop:connect-cms:*:*:*:*:*:*:*:*

History

24 Mar 2026, 20:40

Type Values Removed Values Added
Summary
  • (es) Connect-CMS es un sistema de gestión de contenido. En versiones de la serie 1.x hasta la 1.41.0 inclusive y versiones de la serie 2.x hasta la 2.41.0 inclusive, un problema de autorización impropia en la función de actualización de perfil Mi Página puede permitir la modificación de información de usuario arbitraria. Las versiones 1.41.1 y 2.41.1 contienen un parche.
CPE cpe:2.3:a:opensource-workshop:connect-cms:*:*:*:*:*:*:*:*
First Time Opensource-workshop connect-cms
Opensource-workshop
References () https://github.com/opensource-workshop/connect-cms/commit/7c9951738c62a1d51b91e9956d1eb756c5d52cce - () https://github.com/opensource-workshop/connect-cms/commit/7c9951738c62a1d51b91e9956d1eb756c5d52cce - Patch
References () https://github.com/opensource-workshop/connect-cms/releases/tag/v1.41.1 - () https://github.com/opensource-workshop/connect-cms/releases/tag/v1.41.1 - Release Notes
References () https://github.com/opensource-workshop/connect-cms/releases/tag/v2.41.1 - () https://github.com/opensource-workshop/connect-cms/releases/tag/v2.41.1 - Release Notes
References () https://github.com/opensource-workshop/connect-cms/security/advisories/GHSA-qr6x-wvxr-8hm9 - () https://github.com/opensource-workshop/connect-cms/security/advisories/GHSA-qr6x-wvxr-8hm9 - Vendor Advisory

23 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-23 22:16

Updated : 2026-03-24 20:40


NVD link : CVE-2026-32300

Mitre link : CVE-2026-32300

CVE.ORG link : CVE-2026-32300


JSON object : View

Products Affected

opensource-workshop

  • connect-cms
CWE
CWE-285

Improper Authorization

CWE-639

Authorization Bypass Through User-Controlled Key