Authorization bypass through user-controlled key in DotNetNuke - #VU146088
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to bypass administrative approval for pending user registrations.
The vulnerability exists due to improper access control in the user registration approval process when handling registration approval actions. A remote user can approve pending user accounts to bypass administrative approval for pending user registrations.
This issue affects sites that use administrator approval for new user registrations.