Description
Missing authentication for critical function vulnerability exists in baserCMS . If a remote unauthenticated attacker there is a possibility that sensitive information could be obtained.
Published: 2026-09-30
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a missing authentication check for a critical functionality within baserCMS. A remote attacker who can reach the application without valid credentials can potentially retrieve sensitive information. This flaw aligns with the Authentication Bypass weakness (CWE‑306).

Affected Systems

baserCMS, as distributed by the baserCMS User Community. The affected versions are not specified in the advisory, so all installations of baserCMS should be considered at risk until an updated version is available.

Risk and Exploitability

The CVSS score for this issue is 6.9, reflecting moderate severity. The EPSS score is not available, but the vulnerability is not listed in the CISA KEV catalog. The path of exploitation is inferred to be remote via the web interface, with no authentication required to invoke the function. Because no authentication controls are enforced, an unauthenticated user can exploit this flaw if the vulnerable route is reachable.

Generated by OpenCVE AI on September 30, 2026 at 12:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Ensure baserCMS is updated to the latest release that addresses the authentication issue.
  • If no patch is available, apply access controls to limit exposure of the vulnerable function to authenticated users only.
  • Monitor application and server logs for unauthorized attempts to the affected endpoint.

Generated by OpenCVE AI on September 30, 2026 at 12:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Missing authentication for critical function leading to potential sensitive data exposure in baserCMS

Wed, 30 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Basercms Users Community
Basercms Users Community basercms
Vendors & Products Basercms Users Community
Basercms Users Community basercms

Wed, 30 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description Missing authentication for critical function vulnerability exists in baserCMS . If a remote unauthenticated attacker there is a possibility that sensitive information could be obtained.
Weaknesses CWE-306
References
Metrics cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Basercms Users Community Basercms
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-30T07:42:31.658Z

Reserved: 2026-09-18T01:11:35.023Z

Link: CVE-2026-93462

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T08:16:35.793

Modified: 2026-09-30T08:16:35.793

Link: CVE-2026-93462

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:30:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function