Authentication Vulnerability in Feehi CMS REST API Endpoint
CVE-2026-13546
Key Information:
Badges
What is CVE-2026-13546?
A vulnerability exists in Feehi CMS versions up to 2.1.1 affecting the REST API Endpoint used for handling articles. This issue results from missing authentication mechanisms in the /api/articles file, allowing unauthorized remote access. Attackers can exploit this vulnerability to manipulate requests without proper validation, leading to potential data breaches and unauthorized operations. The problem has been reported to the maintainers, yet no response has been observed, heightening the urgency for users to address this security risk promptly.
Affected Version(s)
CMS 2.1.0
CMS 2.1.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
