Authorization bypass through user-controlled key in DotNetNuke - #VU146091

 

Authorization bypass through user-controlled key in DotNetNuke - #VU146091

Published: August 28, 2026


Vulnerability identifier: #VU146091
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify another group\'s information.

The vulnerability exists due to authorization bypass through user-controlled key in the Social Groups module GroupEdit functionality when processing tampered postback data during group management operations. A remote user can submit a tampered postback request to modify another group\'s information.

Successful exploitation can result in unauthorized changes to editable group information and may be used to publish misleading content that appears to originate from legitimate group owners or administrators.


Affected software

DotNetNuke

Remediation

Install security update from vendor's website.

DotNetNuke - update to 10.3.3

External References

Related Security Bulletins