Authorization bypass through user-controlled key in DotNetNuke - #VU146091
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to modify another group\'s information.
The vulnerability exists due to authorization bypass through user-controlled key in the Social Groups module GroupEdit functionality when processing tampered postback data during group management operations. A remote user can submit a tampered postback request to modify another group\'s information.
Successful exploitation can result in unauthorized changes to editable group information and may be used to publish misleading content that appears to originate from legitimate group owners or administrators.