CVE-2026-8737: Sanluan PublicCMS Trade Address Query TradeAddressListDirective.java execute missing authentication
A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/trade/TradeAddressListDirective.java of the component Trade Address Query Handler. Executing a manipulation of the argument userId/id can lead to missing authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enforce authentication and authorization in TradeAddressListDirective.execute: validate that the request is authenticated and that the authenticated user matches the provided userId/id parameter; reject or return an error for requests that fail these checks.
Sanluan PublicCMS - Trade Address Query Handler (TradeAddressListDirective.execute) authentication_required_for_userId = true - Configuration
Temporarily disable or block access to the TradeAddressListDirective endpoint (the Trade Address Query handler) until a proper code fix or vendor patch is available.
Sanluan PublicCMS - Trade Address Query Handler (TradeAddressListDirective) enabled = false - Compensating control
Apply network-level mitigations: restrict access to the Trade Address Query endpoint using firewall rules, WAF rules, or IP allowlists to limit remote access and reduce exposure to the publicly known exploit.
- Operational
Monitor and audit access logs for the TradeAddressListDirective/related endpoints for signs of exploitation; investigate any suspicious activity and follow incident response procedures if compromise is detected.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8737?
CVE-2026-8737 is considered a high severity vulnerability due to its impact on authentication mechanisms.
How do I fix CVE-2026-8737?
To fix CVE-2026-8737, update Sanluan PublicCMS to the latest version that addresses this vulnerability.
What is affected by CVE-2026-8737?
CVE-2026-8737 affects Sanluan PublicCMS version 5.202506.d, specifically the TradeAddressListDirective.java file.
What are the consequences of CVE-2026-8737?
The consequences of CVE-2026-8737 include unauthorized access to sensitive trade address information.
Is CVE-2026-8737 easy to exploit?
Yes, CVE-2026-8737 can be relatively easy to exploit due to missing authentication controls.