CVE-2026-63301
Last modified
CVE-2026-63301 is a high-severity vulnerability rated 7/10 on the CVSS scale. In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result, an authenticated administrator can bypass the UI-level restriction and delete the primary language by sending a direct HTTP request to the API endpoint. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result, an authenticated administrator can bypass the UI-level restriction and delete the primary language by sending a direct HTTP request to the API endpoint. Successful deletion of the primary language results in a Denial of Service (DoS) of application. Critically, when combined with a separate Cross-Site Request Forgery (CSRF) vulnerability (CVE-2026-1468) an unauthenticated remote attacker can craft a malicious link, which if visited by an authenticated administrator, will trigger the DoS condition without direct access to the application The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| OpenSolution | Quick.CMS | <= 6.8.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-63301?
How severe is CVE-2026-63301?
How do I fix CVE-2026-63301?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63296An authorization bypass vulnerability in LXD allows an authe…9.9
- CVE-2026-63297An authorization bypass vulnerability in LXD due to a timing…9.9
- CVE-2026-63298An improper neutralization of special elements vulnerability…9.9
- CVE-2026-63299An authorization bypass vulnerability in LXD allows an authe…9.9
- CVE-2026-6330The ML-KEM ARM64 NEON ciphertext comparison only compares ha…6.5
- CVE-2026-63300An improper validation vulnerability in the instancePostMigr…9.9
- CVE-2026-63302Quick.CMS is vulnerable to Local File Inclusion (LFI) in the…5.1
- CVE-2026-63303A Path Traversal vulnerability exists in Quick.CMS through t…5.1
- CVE-2026-63304AVideo through 29.0 contains an OS command injection vulnera…9.2
- CVE-2026-63305AVideo through 29.0 contains an OS command injection vulnera…9.2
- CVE-2026-63306stoatchat before 0.13.5 contains an unauthenticated server-s…9.2
- CVE-2026-63307Chat2DB before 5.3.0 contains an insecure direct object refe…7.1
Are you affected by CVE-2026-63301?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
