rootpwn

medium · CVSS v3 5.3 · CVSS v4 6.9 · EPSS 0.00292

CVE-2026-96772

CVE-2026-96772 is an information disclosure vulnerability in Intelliants Subrion CMS versions up to 4.2.1. The flaw is triggered by manipula

Overview

CVE-2026-96772 is an information disclosure vulnerability in Intelliants Subrion CMS versions up to 4.2.1. The flaw is triggered by manipulating the 'q' parameter in /actions.json?action=assign-owner, allowing remote attackers to retrieve sensitive data. The vulnerability is publicly known and unpatched.

Description

A security flaw has been discovered in Intelliants Subrion CMS up to 4.2.1. This affects an unknown part of the file /actions.json?action=assign-owner. The manipulation of the argument q results in information disclosure. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Impact

Confidentiality: sensitive data may be exposed to unauthenticated remote users. Availability: not directly impacted. Integrity: not directly impacted. Defenders should monitor for unauthorized data access and apply the vendor patch when available.

Remediation

Apply the official patch or upgrade to Subrion CMS 4.3 or later. If a patch is not available, restrict access to /actions.json via a web‑application firewall or IP whitelisting, and disable the assign‑owner action if it is not required.

Risk context

Severity is medium (CVSS 5.3) and EPSS is 0.00292, indicating a low probability of exploitation but the vulnerability is publicly disclosed. Defenders should treat it as a low‑to‑moderate risk and prioritize patching accordingly.

Affected products

  • Intelliants Subrion CMS 4.2.1
  • Intelliants Subrion CMS 4.2.0
  • Intelliants Subrion CMS 4.1.x
  • Intelliants Subrion CMS 4.0.x

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
6.9
EPSS
0.00292

information-disclosure remote CMS Intelliants Subrion medium EPSS

← All CVEs