PT-2026-43266 · E107 · E107

·

CVE-2026-43934

·

Published

2026-05-26

·

Updated

2026-05-26

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions e107 versions prior to 2.3.4
Description e107 is a content management system (CMS) containing a broken access control issue. An authenticated user can edit comments posted by other users due to inadequate server-side access control validation. The application relies solely on a predictable identifier in the request to determine the comment to be edited, failing to verify if the requesting user owns the comment.
Recommendations Update to version 2.3.4.

Exploit

Fix

IDOR

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43934
GHSA-5W63-63RH-99Q6

Affected Products

E107