LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-32299

opensource-workshop · connect-cms

Published
CVSS7.5
Severityhigh
WeaknessCWE-284
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Versions 1.41.1 and 2.41.1 contain a patch.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-32299

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-32299.