Description
A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of server-side security. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.5.1 is able to resolve this issue. It is recommended to upgrade the affected component.
Published: 2026-09-02
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists in tsi-coop tsi‑dpdp‑cms versions up to 0.5.0. It causes security to be enforced only on the client side, while the server does not perform proper authentication checks. As a result, an attacker can bypass intended security controls and gain unauthorized access to protected resources or administrative functions. The weakness is classified as CWE‑602.

Affected Systems

The component affected is tsi‑coop tsi‑dpdp‑cms. Versions up to and including 0.5.0 contain the flaw. Upgrading to version 0.5.1 eliminates the vulnerability, as documented in the project’s release notes.

Risk and Exploitability

The CVSS base score is 6.9, indicating moderate severity. The attack can be launched remotely through crafted HTTP requests, and a publicly available exploit has been released, making it a realistic threat for exposed deployments. The vulnerability is not listed in the CISA KEV catalog and no EPSS score is provided, but the combination of a remote attack vector with client‑side enforcement creates a low‑barrier bypass path for attackers.

Generated by OpenCVE AI on September 3, 2026 at 10:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade tsi‑dpdp‑cms to version 0.5.1 or later to apply the vendor‑provided fix.
  • Verify that server‑side authentication is enforced by testing login and authorization flows after the upgrade.
  • Re‑implement or confirm server‑side access controls to prevent future client‑side bypasses.
  • Monitor application logs for anomalous authentication activity to detect potential attempts to circumvent security.

Generated by OpenCVE AI on September 3, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of server-side security. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.5.1 is able to resolve this issue. It is recommended to upgrade the affected component.
Title tsi-coop tsi-dpdp-cms client-side enforcement of server-side security
First Time appeared Tsi-coop
Tsi-coop tsi-dpdp-cms
Weaknesses CWE-602
CPEs cpe:2.3:a:tsi-coop:tsi-dpdp-cms:*:*:*:*:*:*:*:*
Vendors & Products Tsi-coop
Tsi-coop tsi-dpdp-cms
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Tsi-coop Tsi-dpdp-cms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-02T18:45:10.714Z

Reserved: 2026-09-02T11:57:05.309Z

Link: CVE-2026-84841

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-02T19:18:09.580

Modified: 2026-09-03T17:25:25.113

Link: CVE-2026-84841

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T11:30:03Z

Weaknesses
  • CWE-602

    Client-Side Enforcement of Server-Side Security