Description
Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint
Published: 2026-06-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Request Forgery flaw exists within Squidex CMS’s IdentityServer account profile endpoint, allowing a remote attacker to exploit an authenticated user’s session and elevate privileges. Because the endpoint accepts state‑changing requests without an anti‑forgery token, malicious actors can tamper with account settings or assign themselves administrative roles, directly compromising system integrity.

Affected Systems

The vulnerability impacts Squidex CMS versions 7.21.0 and all earlier releases, specifically targeting the IdentityServer component. No other vendors or products are listed as affected.

Risk and Exploitability

The EPSS score is unavailable and the vulnerability is not listed in CISA KEV, but the CSRF nature coupled with privilege escalation capability suggests a significant exploitation likelihood against authenticated users. The CVSS score of 6.5 indicates medium severity. In the absence of a public patch, the risk remains high until the software is updated or mitigated with additional controls.

Generated by OpenCVE AI on June 30, 2026 at 00:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure the application to require anti‑forgery tokens on state‑changing requests to the IdentityServer account profile endpoint.
  • Enforce strict role‑based access control on account profile modifications so that only privileged users can edit settings or assign roles.
  • Conduct regular access reviews to verify user permissions and detect anomalous changes.

Generated by OpenCVE AI on June 30, 2026 at 00:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Squidex.io
Squidex.io squidex
Vendors & Products Squidex.io
Squidex.io squidex

Tue, 30 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery in Squidex CMS Enables Privilege Escalation

Mon, 29 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery Enabling Privilege Escalation in Squidex CMS Cross‑Site Request Forgery in Squidex CMS Enables Privilege Escalation
Weaknesses CWE-285

Mon, 29 Jun 2026 22:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery Enabling Privilege Escalation in Squidex CMS
Weaknesses CWE-285

Mon, 29 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint
References

Subscriptions

Squidex.io Squidex
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-29T20:39:16.456Z

Reserved: 2026-03-09T00:00:00.000Z

Link: CVE-2026-31016

cve-icon Vulnrichment

Updated: 2026-06-29T20:39:11.649Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T10:04:37Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)