Missing Authorization in DotNetNuke - #VU146089

 

Missing Authorization in DotNetNuke - #VU146089

Published: August 28, 2026


Vulnerability identifier: #VU146089
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to interact with private journal posts without authorization.

The vulnerability exists due to missing authorization in the Journal module when recording likes on private journal posts. A remote user can add a like to a private journal entry they are not authorized to access to interact with private journal posts without authorization.

The issue does not expose the contents of private journal posts or allow modification of their content, but it may create visible interactions associated with private activity.


Affected software

DotNetNuke

Remediation

Install security update from vendor's website.

DotNetNuke - update to 10.3.3

External References

Related Security Bulletins