CVE-2026-32300: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-32300 is an improper authorization vulnerability in the My Page profile update feature of Connect-CMS, an open-source content management system developed by opensource-workshop. The flaw allows authenticated users with low privileges to modify arbitrary user profile information, including passwords, potentially enabling full account takeover. Affected versions include the 1.x series up to and including 1.41.0 and the 2.x series up to and including 2.41.0. The vulnerability was disclosed on March 23, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 8.1 (High) (Github Advisory, GitHub Security Advisory).

Technical details

The root cause is classified as CWE-285 (Improper Authorization) and CWE-639 (Authorization Bypass Through User-Controlled Key). In the vulnerable ProfileMypage.php controller, the update() method accepted a user ID directly from the URL path parameter ($id) and used it to look up and update the target user record via User::where('id', $id)->first(), without verifying that the ID matched the currently authenticated user. An attacker could craft a POST request to /mypage/profile/update/{victim_id} substituting any valid user's ID to modify that user's profile or password. The fix replaces the URL-supplied ID with Auth::user() to ensure only the authenticated user's own record is updated (GitHub Commit, Github Advisory).

Impact

Successful exploitation allows an authenticated low-privileged attacker to modify any user's profile information or password, leading to full account takeover of arbitrary users including administrators. This results in high confidentiality impact (access to victim account data and credentials) and high integrity impact (unauthorized modification of user records), with no direct availability impact. Privilege escalation is a realistic outcome if an attacker targets administrative accounts, potentially compromising the entire CMS installation (Github Advisory, GitHub Security Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (Github Advisory). The vulnerability requires the attacker to be authenticated (low-privilege account sufficient) and able to reach the My Page profile update functionality. The EPSS score is approximately 0.016% (4th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Obtain a low-privilege account: Register or obtain credentials for any authenticated user account on the target Connect-CMS instance running a vulnerable version (≤1.41.0 or ≤2.41.0).
  2. Identify target user IDs: Enumerate valid user IDs through observable application behavior (e.g., profile page URLs, user listings, or incremental ID guessing).
  3. Craft a malicious POST request: Authenticate to the application and send a POST request to /mypage/profile/update/{victim_user_id}, substituting the victim's numeric user ID in the URL path.
  4. Supply modified profile data: Include the desired profile fields (e.g., name, userid, email, or password) in the POST body to overwrite the victim's account information.
  5. Achieve account takeover: With the victim's password changed, log in as the victim user. If the targeted account is an administrator, full CMS administrative access is obtained (GitHub Security Advisory, GitHub Commit).

Indicators of compromise

  • Network: Authenticated POST requests to /mypage/profile/update/{id} where the {id} in the URL does not match the authenticated session user's own ID; repeated profile update requests targeting multiple different user IDs from a single session.
  • Logs: Web server or application access logs showing POST requests to /mypage/profile/update/ with varying numeric IDs from the same authenticated session; unexpected profile update events for administrative or high-value accounts.
  • Application: Unexpected changes to user email addresses, passwords, or profile fields — particularly for accounts that did not initiate the change; admin accounts with modified credentials or contact information not matching expected values.

Mitigation and workarounds

Upgrade Connect-CMS to version 1.41.1 (for the 1.x series) or 2.41.1 (for the 2.x series), both released on March 23, 2026, which contain the fix for this vulnerability (GitHub Release v1.41.1, GitHub Release v2.41.1). No configuration-based workaround is available; patching is the only remediation. As interim measures, restrict access to the Connect-CMS instance to trusted networks, review access logs for unauthorized profile modification activity, and monitor administrative accounts for unexpected changes.

Community reactions

The vulnerability was reported by Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc., and credited in the official advisory (Github Advisory). The disclosure was noted by automated vulnerability tracking services including CVE Feed, VulDB, and CIRCL, with limited broader community discussion given the niche nature of the affected software.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management