CVE-2026-9376: JPress UCenter Article Submission Endpoint doWriteSave improper authorization
A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the component UCenter Article Submission Endpoint. Executing a manipulation of the argument id/userId can lead to improper authorization. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
JPress UCenter Article Submission Endpointfrom your environment.If the UCenter Article Submission Endpoint is not required, uninstall or remove the component to eliminate exposure to the vulnerability.
- Configuration
Disable the /ucenter/article/doWriteSave endpoint or restrict its access to authorized administrator IPs/users until a vendor fix is available.
JPress UCenter Article Submission Endpoint (/ucenter/article/doWriteSave) endpoint_access = disabled or restricted - Compensating control
Block or restrict access to /ucenter/article/doWriteSave at the network perimeter (firewall, load balancer) and/or create WAF rules to detect and block exploit attempts targeting the endpoint.
- Operational
Monitor logs for requests to /ucenter/article/doWriteSave and indicators of exploitation (suspicious id/userId manipulations). Investigate any suspicious activity and perform incident response (isolate affected hosts, restore from known-good backups) if compromise is suspected.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9376?
The severity of CVE-2026-9376 is rated as medium with a score of 6.3.
What is the impact of CVE-2026-9376?
CVE-2026-9376 allows an attacker to exploit improper authorization in JPress to manipulate the article submission endpoint.
How do I fix CVE-2026-9376?
To fix CVE-2026-9376, update the JPress software to version 1.0.4 or later, which addresses the improper authorization issue.
What software is affected by CVE-2026-9376?
The software affected by CVE-2026-9376 is JPress versions up to and including 1.0.3.
Can CVE-2026-9376 be exploited remotely?
Yes, CVE-2026-9376 can be exploited remotely, allowing unauthorized access to the article submission functionality.