Access Control Vulnerability in Maccms Product by Magicblack
CVE-2026-75465
7.5HIGH
What is CVE-2026-75465?
The Maccms v10 product includes an access control vulnerability in the /api.php/user/get_list endpoint, where it fails to enforce authentication or authorization checks. This flaw allows unauthenticated attackers to exploit the endpoint by sending specially crafted HTTP GET requests. By manipulating the limit and offset parameters, attackers can paginate through the results and gain unauthorized access to sensitive data, including the information of all registered users. This creates a significant risk for user privacy and data security.
