CVE-2026-1978

A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the file /data/pagesdata.txt of the component User Information Handler. Performing a manipulation results in direct request. It is possible to initiate the attack remotely. The exploit is now public and may be used. You should change the configuration settings.
References
Link Resource
https://github.com/kalyan02/NanoCMS/ Product
https://github.com/kalyan02/NanoCMS/blob/master/data/pagesdata.txt Product
https://vuldb.com/?ctiid.344500 Permissions Required VDB Entry
https://vuldb.com/?id.344500 Third Party Advisory VDB Entry
https://vuldb.com/?submit.743260 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:kalyan02:nanocms:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-06 05:16

Updated : 2026-02-27 20:10


NVD link : CVE-2026-1978

Mitre link : CVE-2026-1978

CVE.ORG link : CVE-2026-1978


JSON object : View

Products Affected

kalyan02

  • nanocms
CWE
CWE-425

Direct Request ('Forced Browsing')