CVE-2026-13544: Feehi CMS API users access control
A flaw has been found in Feehi CMS up to 2.1.1. Affected by this issue is some unknown functionality of the file /api/users of the component API. This manipulation causes improper access controls. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13544?
CVE-2026-13544 has a medium severity rating of 6.3.
How do I fix CVE-2026-13544?
To fix CVE-2026-13544, upgrade Feehi CMS to the latest version that addresses this vulnerability.
What are the potential impacts of CVE-2026-13544?
CVE-2026-13544 may lead to improper access controls allowing unauthorized users to manipulate the API.
Who is affected by CVE-2026-13544?
All users of Feehi CMS versions up to 2.1.1 are affected by CVE-2026-13544.
Can CVE-2026-13544 be exploited remotely?
Yes, CVE-2026-13544 can be exploited remotely by manipulating the API access controls.