Improper Authentication Vulnerability in light0011 CMS by Light0011
CVE-2026-86306
Key Information:
Badges
What is CVE-2026-86306?
A vulnerability has been discovered in the light0011 CMS, specifically within the Cookie Helper component. An issue in the UserModel.class.php file allows attackers to manipulate the Username argument, leading to improper authentication. This issue can potentially be exploited remotely. The affected version utilizes a rolling release model, meaning detailed version information is not readily available. Despite early notification of the problem from the community, there has yet to be a response or patch from the developers.
Affected Version(s)
cms c774dce31c6df0055568a8d5c53d964d99be199d
cms f72cf46f601efb2a0618c3814cc2f61380b38930
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
