SB2026042130 - Multiple vulnerabilities in October CMS



SB2026042130 - Multiple vulnerabilities in October CMS

Published: April 21, 2026

Security Bulletin ID SB2026042130
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Improper access control (CVE-ID: CVE-2026-29179)

The vulnerability allows a remote user to manipulate asset or blueprint files and disclose directory structure information.

The vulnerability exists due to improper access control in the CMS and Tailor editor extensions when handling asset and blueprint file operations and Tailor navigation checks. A remote privileged user can perform create, delete, rename, move, or upload operations on theme assets or blueprint files, or view the theme blueprint navigation tree, to manipulate asset or blueprint files and disclose directory structure information.

This only affects backend users with editor access who were specifically denied the editor.cms_assets or editor.tailor_blueprints sub-permissions.


2) Cross-site scripting (CVE-ID: CVE-2026-27937)

The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.

The vulnerability exists due to improper neutralization of input during web page generation in the backend DataTable widget when rendering a query parameter in a backend URL. A remote attacker can send a specially crafted URL to execute arbitrary script in the victim's browser.

User interaction is required, and the attacker must know or guess the customized backend URL prefix.


Remediation

Install update from vendor's website.