Authorization bypass through user-controlled key in Forum - CVE-2026-77143

 

Authorization bypass through user-controlled key in Forum - CVE-2026-77143

Published: August 26, 2026


Vulnerability identifier: #VU145752
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-77143
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified. A remote attacker can submit a modified update request for that topic directly and overwrite its content.


Affected software

Forum

How to mitigate CVE-2026-77143

Install updates from vendor's website.

Forum - addressed in versions 4.0.4, 5.0.1, 6.2.4

External References

Related Security Bulletins