Description
A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+server.ts of the component User Attribute Update Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The name of the patch is 05b4f9efeb79e9d72a693232334d7529687f896f. It is advisable to implement a patch to correct this issue.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is located in the User Attribute Update Endpoint of SveltyCMS 0.0.6, specifically within src/routes/api/[...path]/+server.ts. It allows an attacker to manipulate the endpoint without proper access checks, leading to unauthorized changes to user attributes. This flaw can enable privilege escalation or compromise of user accounts, as an attacker can set roles or permissions that should be restricted. The weakness is classified as improper authorization (CWE-284) and lack of privilege control (CWE-266).

Affected Systems

SveltyCMS version 0.0.6 is affected. Any installation using this version is potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, but the attack vector is remote, meaning an adversary can exploit the flaw from outside the network. The EPSS score is < 1%, indicating a very low exploitation probability. The vulnerability has not been reported in the CISA KEV catalog, suggesting it may not have been widely exploited yet; however, the lack of access controls still presents a real risk for organizations that rely on the User Attribute Update Endpoint without additional safeguards.

Generated by OpenCVE AI on September 19, 2026 at 19:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch contained in commit 05b4f9efeb79e9d72a693232334d7529687f896f to update SveltyCMS to a secure version
  • Restrict the User Attribute Update Endpoint so that only authenticated users with administrative privileges can modify user attributes
  • Verify that role and permission changes cannot be performed by non‑admin accounts
  • Monitor application logs for suspicious updates to user attributes

Generated by OpenCVE AI on September 19, 2026 at 19:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+server.ts of the component User Attribute Update Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The name of the patch is 05b4f9efeb79e9d72a693232334d7529687f896f. It is advisable to implement a patch to correct this issue.
Title SveltyCMS User Attribute Update Endpoint +server.ts access control
First Time appeared Sveltycms
Sveltycms sveltycms
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:sveltycms:sveltycms:*:*:*:*:*:*:*:*
Vendors & Products Sveltycms
Sveltycms sveltycms
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Sveltycms Sveltycms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-23T16:17:35.573Z

Reserved: 2026-09-18T08:26:43.878Z

Link: CVE-2026-93504

cve-icon Vulnrichment

Updated: 2026-09-23T16:17:06.876Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T14:19:08.027

Modified: 2026-09-23T17:17:19.813

Link: CVE-2026-93504

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:45:11Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control