CodeIgniter 4-based CMS Skeleton Vulnerability Affecting CI4MS
CVE-2026-41891

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
7 May 2026

What is CVE-2026-41891?

CI4MS is a modular content management system built on CodeIgniter 4 that supports role-based access control (RBAC) and theming. An authorization oversight exists in versions 0.26.0 to just before 0.31.8.0, where the check for deactivated or banned users has been improperly commented out in the authentication filter. This flaw could allow unauthorized users to potentially access restricted areas of the application. The issue has been resolved in version 0.31.8.0, where the necessary checks were reinstated, enhancing overall security.

Affected Version(s)

ci4ms >= 0.26.0, < 0.31.8.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.