Improper access control in Smart Content - CVE-2026-96386

 

Improper access control in Smart Content - CVE-2026-96386

Published: September 24, 2026


Vulnerability identifier: #VU151908
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-96386
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the Smart Content Block submodule does not sufficiently check block access when it renders the blocks of a "Display Blocks" reaction through the module's AJAX endpoint. A remote attacker can gain access to sensitive information on the system.


Affected software

Smart Content

How to mitigate CVE-2026-96386

Install updates from vendor's website.

Smart Content - update to 3.2.1

External References

Related Security Bulletins