CVE-2026-4514

MEDIUM

PbootCMS Backend UserController.php access control

Title source: cna

Description

A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the component Backend. Executing a manipulation of the argument Field can lead to improper access controls. The attack may be performed from remote. The exploit has been published and may be used.

Scores

CVSS v3 6.3
EPSS 0.0004
EPSS Percentile 13.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-266 CWE-284
Status published
Products (13)
n/a/PbootCMS 3.2.0
n/a/PbootCMS 3.2.1
n/a/PbootCMS 3.2.10
n/a/PbootCMS 3.2.11
n/a/PbootCMS 3.2.12
n/a/PbootCMS 3.2.2
n/a/PbootCMS 3.2.3
n/a/PbootCMS 3.2.4
n/a/PbootCMS 3.2.5
n/a/PbootCMS 3.2.6
... and 3 more
Published Mar 21, 2026
Tracked Since Mar 21, 2026