CVE-2026-30452
MEDIUMTextpattern CMS 4.9.0 - Privilege Escalation
Title source: llmDescription
Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privileges to modify articles owned by users with higher privileges. By manipulating the article ID parameter during the duplicate-and-save workflow in textpattern/include/txp_article.php, an attacker can bypass authorization checks and overwrite content belonging to other users.
Scores
CVSS v3
6.5
EPSS
0.0003
EPSS Percentile
7.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-284
Status
published
Published
Apr 21, 2026
Tracked Since
Apr 21, 2026