CVE-2026-4514Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the component Backend. Executing a manipulation of the argument Field can lead to improper access controls. The attack may be performed from remote. The exploit has been published and may be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-21); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-21: 3Mentions · 2026-03-22: 1Patch / Workaround · 2026-03-21: 1Technical Details · 2026-03-21: 303-2103-22
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-213
Disclosure2Patch1
2026-03-221
General1
Full discourse4 posts
  • CVE@CVEnew
    General

    CVE-2026-4514 A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the … https://www.cve.org/CVERecord?id=CVE-2026-4514

    Post summary

    The post reports a discovered flaw in PbootCMS affecting a controller file but provides no technical details, exploitation evidence, or patch information.

    0000071
    56.8K followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 Atenção, profissionais de segurança! PbootCMS (≤ 3.2.12) tem uma vulnerabilidade crítica (CVE-2026-4514) que permite manipulação remota do backend. Atualizem para evitar compromissos sérios! 🛡️ Saiba como mitigar: [link]. #Cybersecurity #Vulnerability #PbootCMS

    Post summary

    The post discloses a critical remote-frontend manipulation vulnerability (CVE‑2026‑4514) in PbootCMS ≤3.2.12 and urges users to update or follow the provided mitigation link to prevent serious compromises.

    0000028
    259 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4514 - PbootCMS Backend UserController.php access control Intel Report: https://ift.tt/HuQnqOV

    Post summary

    The post alerts on CVE-2026-4514, a PbootCMS backend access control flaw, and points to an intel report but provides no PoC, exploit code, or evidence of active attacks.

    0000023
    334 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4514 Remote Access Control Bypass in PbootCMS Backend User Controller 3.2.12 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4514 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The notice links to Vulmon details of CVE‑2026‑4514, describing a Remote Access Control Bypass in PbootCMS 3.2.12, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000042
    4.0K followersView on X

Explore more