CVE-2026-43934

e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized authenticated user to edit comments posted by others. This stems from inadequate server-side access control validation, where the application depends only on a predictable identifier in the request to determine which comment to edit, without confirming the requesting user’s ownership of the comment. This vulnerability is fixed in 2.3.4.
Configurations

No configuration.

History

26 May 2026, 18:16

Type Values Removed Values Added
References () https://github.com/e107inc/e107/security/advisories/GHSA-5w63-63rh-99q6 - () https://github.com/e107inc/e107/security/advisories/GHSA-5w63-63rh-99q6 -

26 May 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-26 16:16

Updated : 2026-05-26 19:29


NVD link : CVE-2026-43934

Mitre link : CVE-2026-43934

CVE.ORG link : CVE-2026-43934


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control

CWE-639

Authorization Bypass Through User-Controlled Key