Missing Authorization in baserCMS - CVE-2026-93462
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization checks in BlogCommentsService::getIndex() when handling requests to the public blog comments list API. A remote attacker can send a request to the list endpoint to disclose unapproved comment contents and submitter email addresses.
The issue is limited to the list endpoint; the single-record endpoint applies the comment approval check.