Description
Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.
Published: 2026-09-13
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Access
Action: Immediate Patch
AI Analysis

Impact

Rhymix versions before 2.1.31 contain an insecure direct object reference flaw that permits an attacker to request arbitrary files on the host by appending additional query variables to a URL. The flaw can expose sensitive system and configuration files to an unauthenticated user, resulting in a confidentiality breach. This weakness is classified as CWE‑425.

Affected Systems

The affected product is Rhymix, an open‑source content management framework. Deployments running any Rhymix release older than 2.1.31 are vulnerable. Updates through 2.1.31 and later contain a fix that removes the insecure direct access path and validates request parameters.

Risk and Exploitability

The CVSS score of 7.4 classifies the issue as high severity. The EPSS score is reported as less than 1 percent, indicating a low probability of exploitation in the current threat landscape. The vulnerability is not listed in the CISA KEV catalog. Because the flaw can be triggered by any user who can craft a web request, it is potentially exploitable from the internet without authentication, giving the attacker broad reach.

Generated by OpenCVE AI on September 15, 2026 at 17:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Rhymix to version 2.1.31 or newer.
  • Until an upgrade can be applied, restrict the vulnerable endpoint to trusted IPs or use a web application firewall to block unauthorized requests.
  • Implement strict validation or sanitization of query parameters to prevent unintended variables from being interpreted.

Generated by OpenCVE AI on September 15, 2026 at 17:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Insecure Direct Object Reference in Rhymix Allows Arbitrary File Access

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Arbitrary File Access via Insecure Direct Object Reference in Rhymix
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Title Arbitrary File Access via Insecure Direct Object Reference in Rhymix

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.
First Time appeared Rhymix
Rhymix rhymix
Weaknesses CWE-425
CPEs cpe:2.3:a:rhymix:rhymix:*:*:*:*:*:*:*:*
Vendors & Products Rhymix
Rhymix rhymix
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T15:53:00.695Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36453

cve-icon Vulnrichment

Updated: 2026-09-14T15:52:56.502Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T21:16:59.947

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-36453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:45:17Z

Weaknesses
  • CWE-425

    Direct Request ('Forced Browsing')