CVE-2026-32300

HIGH

Connect-CMS 1.x-1.41.0/2.x-2.41.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Versions 1.41.1 and 2.41.1 contain a patch.

Scores

CVSS v3 8.1
EPSS 0.0001
EPSS Percentile 2.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-285 CWE-639
Status published
Products (4)
opensource-workshop/connect-cms 0 - 1.41.1Packagist
opensource-workshop/connect-cms 1.0.0 - 1.41.1
opensource-workshop/connect-cms < 1.41.1
opensource-workshop/connect-cms >= 2.0.0, < 2.41.1
Published Mar 23, 2026
Tracked Since Mar 24, 2026