Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privileges to modify articles owned by users with higher privileges. By manipulating the article ID parameter during the duplicate-and-save workflow in textpattern/include/txp_article.php, an attacker can bypass authorization checks and overwrite content belonging to other users.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Users Can Bypass Access Control to Alter Higher-Privilege Articles in Textpattern CMS 4.9.0 |
Wed, 22 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Tue, 21 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Textpattern
Textpattern textpattern |
|
| Vendors & Products |
Textpattern
Textpattern textpattern |
Tue, 21 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privileges to modify articles owned by users with higher privileges. By manipulating the article ID parameter during the duplicate-and-save workflow in textpattern/include/txp_article.php, an attacker can bypass authorization checks and overwrite content belonging to other users. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-04-21T00:00:00.000Z
Updated: 2026-04-22T15:35:46.859Z
Reserved: 2026-03-04T00:00:00.000Z
Link: CVE-2026-30452
Updated: 2026-04-22T14:11:33.472Z
Status : Awaiting Analysis
Published: 2026-04-21T17:16:36.303
Modified: 2026-04-22T21:24:26.997
Link: CVE-2026-30452
No data.