CVE-2026-21429

MEDIUM

Emlog - Missing Authorization

Title source: rule
STIX 2.1

Description

Emlog is an open source website building system. In version 2.5.23, the admin can set controls which makes users unable to edit or delete their articles after publishing them. As of time of publication, no known patched versions are available.

References (1)

Core 1
Core References
Exploit, Vendor Advisory x_refsource_confirm
https://github.com/emlog/emlog/security/advisories/GHSA-jw5v-2g53-rx8w

Scores

CVSS v3 4.3
EPSS 0.0005
EPSS Percentile 14.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
emlog/emlog 2.5.23
Published Jan 02, 2026
Tracked Since Feb 18, 2026