LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-32300

CVE-2026-32300 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: March 23, 2026

Connect-CMS - Broken Access Control

Published: March 23, 2026Updated: March 23, 2026Remote Exploitable

Overview

Connect-CMS 1.x <= 1.41.0 and 2.x <= 2.41.0 contain an improper authorization vulnerability in the My Page profile update feature, letting attackers modify arbitrary user information, exploit requires user authentication.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Attackers can modify arbitrary user information, potentially leading to privilege escalation or data tampering.

Mitigation

Upgrade to versions 1.41.1 or 2.41.1 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 23, 2026

🟠 CVE-2026-32300 - High (8.1) Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the My Page profile update feature may allow modific... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-32300/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 23, 2026

🟠 CVE-2026-32300 - High (8.1) Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the My Page profile update feature may allow modific... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-32300/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-32300
Severity
High
CVSS Score
8.1
Type
broken_access_control
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-285

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS Score

0.0%Probability of exploitation in the next 30 days