CVE-2026-15516: MacCMS Pro Installation Index.php step5 authorization
A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit is now public and may be used. Upgrading to version 2022.1000.3025 is recommended to address this issue. Upgrading the affected component is recommended.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MacCMS Proto a version that resolves this vulnerability.Fixed in 2022.1000.3025
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15516?
The severity of CVE-2026-15516 is rated as medium, with a score of 5.6.
How does CVE-2026-15516 affect systems?
CVE-2026-15516 allows for an authorization bypass during the installation process that can be exploited remotely.
What versions of MacCMS Pro are affected by CVE-2026-15516?
CVE-2026-15516 affects MacCMS Pro versions up to 2022.1000.3005.
How can I mitigate CVE-2026-15516?
To mitigate CVE-2026-15516, ensure that you upgrade to a patched version of MacCMS Pro beyond 2022.1000.3005.
What kind of attack can exploit CVE-2026-15516?
An attacker can exploit CVE-2026-15516 by remotely manipulating the authorization process during installation.