PT-2026-86473 · Dynamiapps · Frontend Admin

·

CVE-2026-75816

·

Published

2026-09-06

·

Updated

2026-09-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frontend Admin by DynamiApps versions prior to 3.29.13
Description An authentication bypass allows unauthenticated attackers to take over accounts. The issue occurs because the pre update value function lacks capability or ownership checks, and the ActionPost::conditions logic() function bypasses the current user can('edit post') authorization check when the post ID is non-numeric (for example, using the string user 1). This allows unauthenticated form submissions to be routed to arbitrary user records, enabling attackers to overwrite any user's registered email address, including administrators, and subsequently use the native password-reset process to gain full account access.
Recommendations Update Frontend Admin by DynamiApps to a version newer than 3.29.12.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75816

Affected Products

Frontend Admin