CVE-2026-29179Disclosure

LOWCVSS 3.3 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grained sub-permission checks for asset and blueprint file operations were not enforced in the CMS and Tailor editor extensions. This only affects backend users who were explicitly granted editor access but had editor.cms_assets or editor.tailor_blueprints specifically withheld, an uncommon permission configuration. In this edge case, such users could perform file operations (create, delete, rename, move, upload) on theme assets or blueprint files despite lacking the required sub-permission. A related operator precedence error in the Tailor navigation also disclosed the theme blueprint directory tree under the same conditions. This vulnerability is fixed in 3.7.16 and 4.1.16.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-21); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-21: 2Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-28: 104-2104-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-212
Disclosure2
2026-04-281
Disclosure1
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-29179: CVE-2026-29179: Incorrect Authorization Bypass in October CMS Editor Extensions October CMS versions prior to 3.7.16 and 4.1.16 contain an incorrect authorization vulnerability (CWE-863) within the CMS Editor and Tailor Editor extensio... https://cvereports.com/reports/CVE-2026-29179

    Post summary

    The text announces an incorrect authorization bypass (CWE‑863) in older October CMS Editor extensions and indicates the versions that contain a fix (3.7.16/4.1.16).

    0000021
    36 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-29179 October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grained sub-permission checks for asset and blueprint file operations … https://www.cve.org/CVERecord?id=CVE-2026-29179 ----- Traducción: CVE-2026-29179 Oct… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑29179, describing affected CMS platform versions and missing sub‑permission checks, but provides no evidence of exploitation or remediation.

    0000018
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29179 October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grained sub-permission checks for asset and blueprint file operations … https://www.cve.org/CVERecord?id=CVE-2026-29179

    Post summary

    The content lists the CVE and indicates which CMS versions are affected, providing a brief technical detail but no evidence of exploits or active attacks.

    00000125
    57.2K followersView on X

Explore more