Authorization bypass through user-controlled key in Forum - CVE-2026-77143
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified. A remote attacker can submit a modified update request for that topic directly and overwrite its content.