PT-2026-95364 · Sveltycms · Sveltycms

·

CVE-2026-93504

·

Published

2026-09-18

·

Updated

2026-09-19

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SveltyCMS version 0.0.6
Description Improper access controls exist within the User Attribute Update Endpoint, specifically affecting the file src/routes/api/[...path]/+server.ts. This flaw allows a remote attacker to manipulate the system due to insufficient authorization checks.
Recommendations Apply patch 05b4f9efeb79e9d72a693232334d7529687f896f for version 0.0.6.

Exploit

Fix

Improper Access Control

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93504

Affected Products

Sveltycms