CVE-2026-4514

A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the component Backend. Executing a manipulation of the argument Field can lead to improper access controls. The attack may be performed from remote. The exploit has been published and may be used.
Configurations

No configuration.

History

24 Apr 2026, 16:27

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en PbootCMS hasta la versión 3.2.12. Se ve afectada por este problema alguna funcionalidad desconocida del archivo apps/admin/controller/system/UserController.PHP del componente Backend. La ejecución de una manipulación del argumento Field puede conducir a controles de acceso inadecuados. El ataque puede realizarse de forma remota. El exploit ha sido publicado y puede ser utilizado.

21 Mar 2026, 11:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 11:17

Updated : 2026-06-17 10:56


NVD link : CVE-2026-4514

Mitre link : CVE-2026-4514

CVE.ORG link : CVE-2026-4514


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment

CWE-284

Improper Access Control