Description
A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects an unknown part of the file App/Home/Model/UserModel.class.php of the component Cookie Helper. Executing a manipulation of the argument Username can lead to improper authentication. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-07
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A weakness has been discovered in the light0011 cms application within the Cookie Helper component, specifically in the file App/Home/Model/UserModel.class.php. By manipulating the Username argument, an attacker can trigger improper authentication (CWE-287), allowing them to log in as any user without possessing valid credentials. This vulnerability directly compromises the integrity and confidentiality of user accounts.

Affected Systems

The affected product is light0011 cms. Because the project follows a rolling release model and does not disclose specific versions, the exact versions impacted are unknown. The weakness applies to any deployment of the system that includes the vulnerable Cookie Helper code.

Risk and Exploitability

The CVSS score is 6.9. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, but exploitation code has already been made public and the attack may be performed remotely. The likely attack vector involves sending a crafted Username value, possibly via a cookie or request parameter, to bypass authentication checks. Given the public availability of the exploit, the risk is that unauthenticated users can gain arbitrary access to the application.

Generated by OpenCVE AI on September 7, 2026 at 15:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or upgrade to the corrected version of light0011 cms once the vendor releases it.
  • Implement strict input validation on the Username parameter, limiting characters and length to prevent injection of bypass values.
  • Monitor authentication logs for unexpected logins and consider disabling cookie‑based authentication until a fix is deployed.

Generated by OpenCVE AI on September 7, 2026 at 15:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects an unknown part of the file App/Home/Model/UserModel.class.php of the component Cookie Helper. Executing a manipulation of the argument Username can lead to improper authentication. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.
Title light0011 cms Cookie Helper UserModel.class.php improper authentication
First Time appeared Light0011
Light0011 cms
Weaknesses CWE-287
CPEs cpe:2.3:a:light0011:cms:*:*:*:*:*:*:*:*
Vendors & Products Light0011
Light0011 cms
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-07T13:00:07.849Z

Reserved: 2026-09-06T18:16:45.239Z

Link: CVE-2026-86306

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T13:20:39.927

Modified: 2026-09-07T13:20:39.927

Link: CVE-2026-86306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T15:15:17Z

Weaknesses