Impact
The /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 suffers from an Incorrect Access Control flaw. The endpoint does not perform authentication or authorization checks, allowing any unauthenticated remote attacker to craft a HTTP GET request with limit and offset parameters to paginate and retrieve sensitive data of all registered users, exposing private user information without credentials.
Affected Systems
The vulnerable software is Maccms version 10 identified as v2026.1000.4055. No vendor information is published; the application itself is the affected system. No other product versions are listed.
Risk and Exploitability
The lack of access control means the flaw can be exploited from any network location over HTTP. The EPSS score is <1% and the vulnerability is not listed in CISA KEV. The CVSS score of 7.5 indicates high severity. The risk is high because the vulnerability can be triggered with a simple GET request and results in full data disclosure; exploitation requires no privileged access or specialized prerequisites.
OpenCVE Enrichment