CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-32300

CVE-2026-32300: Insecure Direct Object Reference in Connect-CMS Profile Update

Alon Barad
Alon Barad
Software Engineer

Mar 24, 2026·6 min read·118 visits

Executive Summary (TL;DR)

Authenticated attackers can modify arbitrary user profiles and hijack accounts via an IDOR vulnerability in the Connect-CMS profile update endpoint.

Connect-CMS suffers from an Insecure Direct Object Reference (IDOR) vulnerability within its My Page profile update functionality. The application relies on client-provided user identifiers to determine which profile record to modify, without verifying if the authenticated session holds the requisite permissions. This oversight permits any authenticated user to arbitrarily alter the profile data of other users, creating a direct path to full account takeover.

Vulnerability Overview

Connect-CMS is an open-source content management system that provides user authentication and profile management capabilities. The application exposes a 'My Page' component, which enables authenticated users to view and modify their personal profile information, such as their name, email address, and login identifier.

The vulnerability resides in the profile update routine of this component. Specifically, the application architecture trusts user-supplied input to identify the database record intended for modification. This architectural pattern constitutes an Insecure Direct Object Reference (IDOR), classified under CWE-639 (Authorization Bypass Through User-Controlled Key) and CWE-285 (Improper Authorization).

An attacker with low privileges (a standard authenticated account) can exploit this flaw by submitting a crafted HTTP request to the profile update endpoint. By substituting their own user identifier with the identifier of a target victim, the attacker coerces the application into overwriting the victim's profile data with the attacker's supplied payload. The attack requires no user interaction and operates entirely over the network.

Root Cause Analysis

The fundamental root cause of CVE-2026-32300 is a failure to correlate the object requested for modification with the established session context. The vulnerable code resides within the update method of the ProfileMypage plugin.

When a profile update request is received, the application router extracts a user identifier ($id) directly from the request URL. The controller then uses this unverified $id parameter in a database query to retrieve the user model. The application proceeds to apply the submitted profile changes to the retrieved model and saves the transaction to the database.

The controller entirely omits an authorization check. It does not invoke Laravel's authorization gates, nor does it explicitly verify that the $id from the route matches the identifier of the currently authenticated user (Auth::id()). Consequently, the application blindly executes the update operation on whichever user record corresponds to the URL parameter, relying on the false assumption that users will only interact with the user interface presented to them.

Code Analysis

The source of the vulnerability is clearly visible in the app/Plugins/Mypage/ProfileMypage/ProfileMypage.php file. The vulnerable implementation accepts the $id parameter from the route and uses it directly in the Eloquent ORM query.

public function update($request, $id)
{
    // VULNERABLE: Fetches user based solely on ID from URL parameter
    $user = User::where('id', $id)->first();
    
    // Application logic applies $request data to $user and saves it
}

The upstream maintainers resolved this vulnerability in versions 1.41.1 and 2.41.1 by completely removing the reliance on user-supplied identifiers for profile updates. The patched implementation utilizes the server-side session state to identify the target user record.

public function update($request, $id = null)
{
    // FIXED: Ignores URL $id and binds strictly to the authenticated user session
    $user = Auth::user();
    $user_id = $user->id;
    
    // Application logic applies $request data to the authenticated $user
}

This remediation strategy effectively eliminates the attack vector. By retrieving the User model directly from the Auth facade, the application ensures that users can only ever modify the profile associated with their active session token. The patch is structurally sound and prevents bypasses via parameter pollution or routing manipulation.

Exploitation Methodology

Exploitation of CVE-2026-32300 requires the attacker to possess a valid, authenticated session within the target Connect-CMS instance. The attacker must also discern or enumerate the user identifier of their intended victim. Since user IDs are frequently sequential integers or exposed in public components like comments or article metadata, enumeration is trivial in most deployments.

The attacker crafts an HTTP POST request targeting the profile update endpoint, specifying the victim's identifier in the URL path. The request body contains the attacker's desired values for the profile fields, most notably the email and userid parameters.

The official patch includes a feature test that functions as a programmatic Proof of Concept. This test demonstrates the vulnerability mechanics by simulating an attacker (attacker@example.com) attempting to update the profile of another user (victim@example.com).

public function testProfileUpdatePathIdCannotUpdateAnotherUser(): void
{
    $attacker = User::factory()->create(['email' => 'attacker@example.com']);
    $victim = User::factory()->create(['email' => 'victim@example.com']);
 
    $response = $this->actingAs($attacker)->post("/mypage/profile/update/{$victim->id}", [
        'name' => 'Attacker',
        'userid' => 'attacker-id',
        'email' => 'attacker-updated@example.com',
    ]);
 
    $this->assertSame('attacker-updated@example.com', $attacker->fresh()->email);
    $this->assertSame('victim@example.com', $victim->fresh()->email);
}

Impact Assessment

The vulnerability carries a High severity rating due to its profound impact on application integrity and user confidentiality. By manipulating the IDOR flaw, an attacker gains arbitrary write access to the profile data of any registered user within the system.

The most critical consequence is the potential for complete account takeover. An attacker can overwrite a victim's email address with an address controlled by the attacker. Subsequently, the attacker can invoke the application's standard "Forgot Password" workflow. The password reset token will be delivered to the newly configured attacker-controlled email, granting the attacker full access to the victim's account.

If the targeted victim possesses administrative privileges, this exploit chain escalates the attack from a standard account compromise to full administrative control over the Connect-CMS instance. This enables further malicious actions, including arbitrary content modification, extraction of sensitive database records, and potential remote code execution depending on the administrative features available in the CMS.

Remediation and Mitigation

The definitive resolution for CVE-2026-32300 is to apply the vendor-supplied patches. Organizations operating the 1.x release branch must upgrade to version 1.41.1, while those on the 2.x release branch must upgrade to version 2.41.1. These versions implement strict session-based authorization for profile modifications.

In environments where immediate patching is strictly prohibited by change control processes, mitigating the vulnerability is challenging due to the lack of distinct network signatures. Network defenders can attempt to monitor HTTP POST requests directed at /mypage/profile/update/* and flag anomalies where the path ID diverges from normal usage patterns, though this requires complex correlation with application session data.

Development teams should integrate automated authorization testing into their CI/CD pipelines to prevent regressions. Unit tests and feature tests must explicitly verify that endpoints handling state modifications reject inputs intended for records outside the authenticated user's ownership scope.

Official Patches

opensource-workshopRelease notes and patch for Connect-CMS 1.x
opensource-workshopRelease notes and patch for Connect-CMS 2.x

Fix Analysis (1)

Technical Appendix

CVSS Score
8.1/ 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected Systems

Connect-CMS 1.x up to and including 1.41.0Connect-CMS 2.x up to and including 2.41.0

Affected Versions Detail

Product
Affected Versions
Fixed Version
Connect-CMS
opensource-workshop
<= 1.41.01.41.1
Connect-CMS
opensource-workshop
<= 2.41.02.41.1
AttributeDetail
CWE IDCWE-639 / CWE-285
Attack VectorNetwork
CVSS v3.1 Score8.1 (High)
ImpactHigh Integrity, High Confidentiality
Privileges RequiredLow
Exploit StatusProof of Concept Available
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1212Exploitation for Credential Access
Credential Access
CWE-639
Authorization Bypass Through User-Controlled Key

The system's authorization model fails to adequately verify that a user is permitted to access or modify the requested resource, resulting in an Insecure Direct Object Reference.

Vulnerability Timeline

Fix authored by developer gakigaki
2026-02-20
Version 1.41.1-rc3 released with initial fixes
2026-03-05
Version 1.41.1-rc4 released
2026-03-11
Official security advisory published and patched versions released
2026-03-23

References & Sources

  • [1]GitHub Security Advisory GHSA-qr6x-wvxr-8hm9
  • [2]CVE-2026-32300 Record

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•1 day ago•CVE-2026-58197
8.8

CVE-2026-58197: Host Escape and Lateral Movement via Insecure Container Network Defaults in ToolHive

A high-severity access control vulnerability in ToolHive CLI before v0.30.1 and ToolHive Studio before v0.38.0 allows local containerized MCP servers to bypass network isolation. This enables malicious workloads to establish TCP/IP connections to administrative and control plane endpoints exposed on the host loopback interface.

Amit Schendel
Amit Schendel
8 views•8 min read
•1 day ago•CVE-2026-63405
5.9

CVE-2026-63405: Insufficient Verification of Data Authenticity in AnyCable Pusher REST API

AnyCable is a real-time communication server. Prior to version 1.6.15, its Pusher-compatible REST API suffered from an authentication bypass vulnerability because it failed to verify that the request body matched the signature-validated body_md5 parameter. This allows attackers to perform replay attacks with modified body contents.

Amit Schendel
Amit Schendel
9 views•5 min read
•1 day ago•CVE-2026-64847
6.8

CVE-2026-64847: Indefinite Denial of Service via Undrained Stderr in AnyIO Process Pool Workers

A denial-of-service vulnerability exists in AnyIO prior to version 4.14.2. Standard error streams of process-pool workers are connected to an operating system pipe that is never drained by the parent process. This allows a worker to fill the pipe buffer and deadlock indefinitely.

Amit Schendel
Amit Schendel
8 views•6 min read
•2 days ago•CVE-2026-63349
7.0

CVE-2026-63349: Privilege Dropping Bypass and Denial of Service in AnyIO Subprocess Module

CVE-2026-63349 is a critical privilege-dropping bypass vulnerability in the AnyIO asynchronous framework (versions 4.14.0 and 4.14.1) on POSIX platforms. Due to a variable assignment typo, supplementary groups specified by the developer are not correctly propagated to the execution backend, resulting in subprocesses retaining the parent process's elevated supplementary group permissions.

Alon Barad
Alon Barad
14 views•5 min read
•2 days ago•CVE-2026-63406
5.9

CVE-2026-63406: Information Disclosure via Insecure Telemetry and Hardcoded Credentials in AnyCable-Go

CVE-2026-63406 is an information disclosure vulnerability in AnyCable-go prior to version 1.6.15. The built-in telemetry client is enabled by default with a hardcoded public authentication token ('secret'). This client digests highly sensitive configuration parameters and command-line arguments, including JWT secrets and RPC secrets, into a stable SHA-256 fingerprint. This fingerprint is sent over public networks, exposing those administrative secrets to offline dictionary and brute-force attacks if intercepted.

Alon Barad
Alon Barad
7 views•5 min read
•2 days ago•CVE-2026-84992
6.1

CVE-2026-84992: Cross-Site Scripting (XSS) via Fenced Code Block Parsing in md-editor-v3

CVE-2026-84992 is a Cross-Site Scripting (XSS) vulnerability affecting md-editor-v3 before version 6.5.4. It occurs because the fenced-code block language parser directly interpolates unescaped language metadata into unquoted HTML attributes inside the custom rendering callback. This bypasses the built-in XSSPlugin which runs during the parsing phase, before rendering.

Amit Schendel
Amit Schendel
9 views•6 min read