CVE-2026-52730: Xibo CMS Missing Authorization in Module::settingsForm due to PHP operator precedence
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.3, missing Authorization in Module::settingsForm allows to view (not change) super admin-restricted module settings and leak the full module entity. Exploitation of the vulnerability is possible on behalf of an authorized user who has access to the Module View feature, which are not granted to non-admins as standard. Users should upgrade to version 4.4.3 which fixes this issue. Upgrading to a fixed version is necessary to remediate. Users unable to upgrade should revoke such privileges from users they do not trust.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Xibo CMSto a version that resolves this vulnerability.Fixed in 4.4.3 - Compensating control
For users unable to upgrade, revoke access to the Module View feature and remove Module::settingsForm-related privileges from users you do not trust (note: exploitation requires an authorized user with access to Module View; non-admins do not have this by default).
Event History
Frequently Asked Questions
Who can exploit this issue in practice?
An attacker must be an authorized user with access to the Module View feature. Non-admin users are not granted that feature by default, so environments that have delegated it to non-admin or otherwise untrusted accounts are exposed.
What information can be disclosed?
The issue permits viewing super-admin-restricted module settings and can leak the full module entity. It does not allow the attacker to change those settings.
What should we do if upgrading is not immediately possible?
Revoke Module View privileges from users you do not trust. Upgrading to Xibo CMS 4.4.3 is necessary to remediate the vulnerability.