Description
A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of the component msgWarning Plugin. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-04
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the msgWarning plugin of Kalcaddle Kodbox 1.67 Build 02 allows an attacker to manipulate the /index.php?plugin/msgWarning/action request and bypass normal authorization controls. The vulnerability can be triggered remotely by sending crafted requests, and the published exploit demonstrates its feasibility. As a result, an attacker may gain unauthorized privileges or access to sensitive data exposed by the plugin. The weakness is classified under CWE-266 and CWE-285, indicating inadequate authorisation and privilege management.

Affected Systems

The vulnerable product is Kalcaddle Kodbox version 1.67 Build 02. The flaw exists in the msgWarning Plugin component; no other versions or related products have been identified as affected.

Risk and Exploitability

The CVSS score of 6.9 places this issue in the medium severity range. EPSS data is not available and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, but an exploit has already been published. The remote nature of the attack vector means that anyone with network access to the web application may attempt the manipulation without needing authentication. Given the lack of additional mitigations reported by the vendor, the likelihood of exploitation remains significant if the vulnerable plugin is reachable.

Generated by OpenCVE AI on August 4, 2026 at 09:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Kalcaddle Kodbox to a version that removes the vulnerability in the msgWarning plugin.
  • If a patch is unavailable, block direct traffic to /index.php?plugin/msgWarning/action using a firewall or web‑application firewall rule.
  • Configure the web server to require authentication before accessing the msgWarning plugin endpoint, ensuring only authorized users can invoke the action.
  • Disable or uninstall the msgWarning plugin if it is not required for normal operation.

Generated by OpenCVE AI on August 4, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of the component msgWarning Plugin. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title kalcaddle kodbox msgWarning Plugin action improper authorization
First Time appeared Kalcaddle
Kalcaddle kodbox
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:kalcaddle:kodbox:*:*:*:*:*:*:*:*
Vendors & Products Kalcaddle
Kalcaddle kodbox
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Kalcaddle Kodbox
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-04T14:41:53.692Z

Reserved: 2026-08-03T17:42:15.230Z

Link: CVE-2026-18720

cve-icon Vulnrichment

Updated: 2026-08-04T14:41:42.810Z

cve-icon NVD

Status : Deferred

Published: 2026-08-04T03:16:25.703

Modified: 2026-08-12T20:59:00.027

Link: CVE-2026-18720

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T09:30:06Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization