CVE-2026-9376

A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the component UCenter Article Submission Endpoint. Executing a manipulation of the argument id/userId can lead to improper authorization. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Configurations

No configuration.

History

24 May 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-24 11:16

Updated : 2026-05-26 19:54


NVD link : CVE-2026-9376

Mitre link : CVE-2026-9376

CVE.ORG link : CVE-2026-9376


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment

CWE-285

Improper Authorization