Authorization Bypass Vulnerability in Sanluan PublicCMS
CVE-2026-97721
Key Information:
Badges
What is CVE-2026-97721?
A significant vulnerability exists in Sanluan PublicCMS, affecting versions up to 6.202506.e. This flaw is found in the CmsContentAdminController, specifically in the exportExcel/exportData functionality. An attacker can exploit this vulnerability to bypass authorization controls by manipulating the userId and deptId arguments. This exploitation can occur remotely, making systems utilizing this CMS particularly vulnerable. Publicly available exploit details have raised concerns, as the vendor has not responded to early disclosures regarding this critical issue.
Affected Version(s)
PublicCMS 6.202506.a
PublicCMS 6.202506.b
PublicCMS 6.202506.c
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
