AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-72601

HIGH · CVSS 7.5 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A broken access control vulnerability in CSZ CMS 1.3.2 enables unauthenticated remote attackers to access all form submissions, including sensitive personally identifiable information, through the unprotected admin form-submission viewer. This flaw arises from the absence of an authentication check, allowing attackers to exploit the system without any credentials. Organizations using this CMS should prioritize remediation to protect user data and comply with privacy regulations.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72601
Severity
HIGH
CVSS
7.5
EPSS
0.36%

Original NVD Description

A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions including personally identifiable information via the admin form-submission viewer. The viewer endpoint lacks an authentication check and the framework authentication helper fails open. An unauthenticated attacker can access all contact form submissions without credentials.