Impact
In Quick.CMS the administrative interface hides the option to delete the primary language, but the underlying API does not enforce a server‑side authorization check. An authenticated administrator can therefore bypass the interface restriction by sending a direct HTTP request to delete the primary language, leading to a loss of functionality. The vulnerability is identified as a privilege escalation flaw (CWE‑602). When combined with a separate CSRF flaw (CVE-2026-1468), an unauthenticated remote user can craft a malicious link; an authenticated administrator visiting the link will trigger the DoS without direct application access.
Affected Systems
The vendor product affected is OpenSolution Quick.CMS. No specific product versions were enumerated in the advisory, so all released versions are potentially impacted until an official fix is released.
Risk and Exploitability
The CVSS score of 7 indicates a high severity. The EPSS score of less than 1% reflects a very low exploitation probability, and the vulnerability is not listed in CISA KEV. The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary. The attacker must be authenticated as an administrator to exploit the server‑side flaw; however, the CSRF combination allows an unauthenticated remote attacker to perform the action if a privileged user follows the malicious link. The overall risk is moderate, with a low likelihood of active exploitation, but the potential impact is a complete service outage for affected sites.
OpenCVE Enrichment