CVE-2026-32300

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Versions 1.41.1 and 2.41.1 contain a patch.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:opensource-workshop:connect-cms:*:*:*:*:*:*:*:*
cpe:2.3:a:opensource-workshop:connect-cms:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-23 22:16

Updated : 2026-03-24 20:40


NVD link : CVE-2026-32300

Mitre link : CVE-2026-32300

CVE.ORG link : CVE-2026-32300


JSON object : View

Products Affected

opensource-workshop

  • connect-cms
CWE
CWE-285

Improper Authorization

CWE-639

Authorization Bypass Through User-Controlled Key