CVE-2026-29597General

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

DDSN Interactive cm3 Acora CMS version 10.7.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive configuration files by force browsing the “/Admin/file_manager/file_details.asp” endpoint and manipulating the “file” parameter. By referencing specific files (e.g., cm3.xml), the attacker can retrieve system administrator credentials, SMTP settings, database credentials, and other confidential information. The exposure of this information can lead to full administrative access to the CMS, unauthorized access to email services, compromise of backend databases, lateral movement within the network, and long-term persistence by an attacker. This access control bypass poses a critical risk of account takeover, privilege escalation, and systemic compromise of the affected application and its associated infrastructure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-31)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-30: 1Mentions · 2026-03-31: 2Technical Details · 2026-03-31: 203-3003-31
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-301
General1
2026-03-312
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-29597 Incorrect access control in the file_details.asp endpoint of DDSN Interactive Acora CMS v10.7.1 allows attackers with editor privileges to access sensitive files via … https://www.cve.org/CVERecord?id=CVE-2026-29597 ----- Traducción: CVE-2026-29597 Con… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑29597, outlining an access‑control flaw that lets editor users retrieve sensitive files through a specific endpoint, but it lacks any proof of exploitation, patches, or active attack reports.

    0000026
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29597 Incorrect access control in the file_details.asp endpoint of DDSN Interactive Acora CMS v10.7.1 allows attackers with editor privileges to access sensitive files via … https://www.cve.org/CVERecord?id=CVE-2026-29597

    Post summary

    The text reports a disclosed vulnerability in DDSN Interactive Acora CMS v10.7.1, describing access‑control flaw that could allow privileged users to read sensitive files.

    00000255
    56.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-29597 CVE-2026-29597 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29597

    Post summary

    The entry only lists the CVE number and a link to a vulnerability details page, without any additional information about the vulnerability, exploitation, or mitigation.

    0000055
    4.0K followersView on X

Explore more