CVE-2026-6796: Sanluan PublicCMS Failed Login LoginAdminController.java log_login cleartext storage in file
A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function loglogin of the file core/src/main/java/com/publiccms/controller/admin/LoginAdminController.java of the component Failed Login Handler. This manipulation of the argument errorPassword causes cleartext storage in a file or on disk. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6796?
CVE-2026-6796 has a medium severity rating due to the cleartext storage of sensitive information.
How do I fix CVE-2026-6796?
To mitigate CVE-2026-6796, modify the log_login function to ensure that sensitive data is encrypted before storage.
What software versions are affected by CVE-2026-6796?
CVE-2026-6796 affects Sanluan PublicCMS versions up to and including 6.202506.d.
What type of vulnerability is CVE-2026-6796?
CVE-2026-6796 is a vulnerability related to improper storage of sensitive information in cleartext.
Who is the vendor for CVE-2026-6796?
The vendor for CVE-2026-6796 is Sanluan, responsible for the Sanluan PublicCMS software.