Security Advisory

CVE-2026-72601

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-11 11:14:44
Last updated 2026-08-11 12:13:39
Assigner TuranSec
CVSS score not scored
State PUBLISHED

Description

A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions including personally identifiable information via the admin form-submission viewer. The viewer endpoint lacks an authentication check and the framework authentication helper fails open. An unauthenticated attacker can access all contact form submissions without credentials.