Authorization bypass through user-controlled key in DotNetNuke - #VU146088

 

Authorization bypass through user-controlled key in DotNetNuke - #VU146088

Published: August 28, 2026


Vulnerability identifier: #VU146088
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass administrative approval for pending user registrations.

The vulnerability exists due to improper access control in the user registration approval process when handling registration approval actions. A remote user can approve pending user accounts to bypass administrative approval for pending user registrations.

This issue affects sites that use administrator approval for new user registrations.


Affected software

DotNetNuke

Remediation

Install security update from vendor's website.

DotNetNuke - update to 10.3.3

External References

Related Security Bulletins