User Impersonation Vulnerability in DNN CMS
CVE-2026-40305

4.3MEDIUM

Key Information:

Vendor
CVE Published:
17 April 2026

What is CVE-2026-40305?

A user impersonation vulnerability exists in the DNN platform, allowing an attacker to send a crafted request that results in the unintended acceptance of a friend request by another user. This flaw is present in versions 6.0.0 through 10.2.1 of the DNN CMS. It is crucial for users to upgrade to version 10.2.2, which addresses this issue and strengthens the platform's integrity and user security.

Affected Version(s)

Dnn.Platform >= 6.0.0, < 10.2.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.