Incorrect permission assignment for critical resource in baserCMS - #VU152767
Published: September 29, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to incorrect permission assignment for a critical resource in the bc-mcp plugin's OAuth2Service::generateKeyPair() function when generating the OAuth2 signing key pair. A local user can read the OAuth2 private key and re-sign an access token with altered user_id or scope claims to escalate privileges.
Exploitation requires access to a live, unexpired, and unrevoked token identifier.