High severity7.5NVD Advisory· Published Aug 11, 2026· Updated Aug 11, 2026
CVE-2026-72601
CVE-2026-72601
Description
A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions including personally identifiable information via the admin form-submission viewer. The viewer endpoint lacks an authentication check and the framework authentication helper fails open. An unauthenticated attacker can access all contact form submissions without credentials.
Affected products
1Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.