CVE-2026-57518
HIGHPagekit CMS 1.0.18 Privilege Escalation via UserApiController
Title source: cnaDescription
Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitrary custom roles to themselves due to missing authorization checks in UserApiController::saveAction(). Attackers can assign themselves a custom role with the 'system: manage packages' permission and then upload and install a malicious PHP package through the admin package installer to achieve remote code execution.
References (2)
Core 2
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://gist.github.com/sermikr0/6f0a67e9d101746fcdb04827de137847
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/pagekit-cms-privilege-escalation-via-userapicontroller
Scores
CVSS v3
8.8
EPSS
0.0048
EPSS Percentile
38.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-862
Status
published
Products (1)
pagekit/pagekit
< 1.0.18
Published
Jun 26, 2026
Tracked Since
Jun 26, 2026