CVE-2026-32299

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
23/03/2026
Last modified:
24/03/2026

Description

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Versions 1.41.1 and 2.41.1 contain a patch.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opensource-workshop:connect-cms:*:*:*:*:*:*:*:* 1.0.0 (including) 1.41.1 (excluding)
cpe:2.3:a:opensource-workshop:connect-cms:*:*:*:*:*:*:*:* 2.0.0 (including) 2.41.1 (excluding)