Access Control Vulnerability in Maccms Product by Magicblack
CVE-2026-75465

7.5HIGH

Key Information:

Vendor

Magicblack

Vendor
CVE Published:
25 August 2026

What is CVE-2026-75465?

The Maccms v10 product includes an access control vulnerability in the /api.php/user/get_list endpoint, where it fails to enforce authentication or authorization checks. This flaw allows unauthenticated attackers to exploit the endpoint by sending specially crafted HTTP GET requests. By manipulating the limit and offset parameters, attackers can paginate through the results and gain unauthorized access to sensitive data, including the information of all registered users. This creates a significant risk for user privacy and data security.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.