Authorization bypass through user-controlled key in REDAXO - #VU140849

 

Authorization bypass through user-controlled key in REDAXO - #VU140849

Published: August 4, 2026


Vulnerability identifier: #VU140849
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify other editors' content outside their authorized categories.

The vulnerability exists due to authorization bypass through a user-controlled key in slice operations and related service-layer handlers when processing requests that supply an article reference for permission checks and an independent slice reference for the mutation. A remote user can send a specially crafted request to modify other editors' content outside their authorized categories.

The issue affects deleting slices, changing slice status, moving slices, and, with a matching module/template constellation, overwriting content. The attack is performed entirely within the user's authenticated session and does not require user interaction.


Affected software

REDAXO

Remediation

Install security update from vendor's website.

REDAXO - update to 5.21.4

External References

Related Security Bulletins