CVE-2026-32299

7.5

OpenSource-Workshop · Connect-CMS

An improper access control vulnerability in Connect-CMS allows unauthenticated attackers to retrieve non-public information via the page content retrieval feature.

Executive summary

A critical improper access control flaw in Connect-CMS enables unauthenticated attackers to exfiltrate sensitive, non-public data from affected installations.

Vulnerability

The application fails to properly enforce authorization checks within the page content retrieval feature, allowing any unauthenticated remote attacker to access restricted information.

Business impact

This vulnerability poses a significant risk to data confidentiality, as it permits unauthorized access to potentially sensitive content without requiring authentication. With a CVSS score of 7.5, the vulnerability is classified as High, reflecting the ease of exploitation and the potential for unauthorized data disclosure that could lead to regulatory non-compliance or reputational damage.

Remediation

Immediate Action: Update Connect-CMS to version 1.41.1 or 2.41.1 immediately to resolve the authorization flaw.

Proactive Monitoring: Review web access logs for unusual patterns of traffic directed at page content retrieval endpoints, particularly requests originating from unauthorized or unexpected IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules designed to inspect and restrict access to sensitive content retrieval parameters until the software can be patched.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the ease with which this vulnerability can be exploited by unauthenticated actors, organizations must prioritize patching their Connect-CMS instances. Organizations should move quickly to verify their current version and apply the mandatory security updates to prevent potential data breaches.

Sources