CVE-2026-40305: DNN has Force Friend Request Acceptance
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40305?
CVE-2026-40305 is considered a moderate severity vulnerability due to the potential for unauthorized friend request acceptance.
How do I fix CVE-2026-40305?
To resolve CVE-2026-40305, upgrade to DotNetNuke version 10.2.2 or later.
What versions of DotNetNuke are affected by CVE-2026-40305?
CVE-2026-40305 affects DotNetNuke versions between 6.0.0 and 10.2.2, exclusive.
What are the potential impacts of CVE-2026-40305?
The impact of CVE-2026-40305 includes unauthorized acceptance of friend requests, potentially leading to user privacy violations.
Is there a workaround for CVE-2026-40305?
There are no documented workarounds for CVE-2026-40305, so upgrading is the recommended solution.