CVE-2026-15516: Authorization Bypass in MacCMS Pro
A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit is now public and may be used. Upgrading to version 2022.1000.3025 is recommended to address this issue. Upgrading the affected component is recommended.
AI Analysis
Technical Summary
This vulnerability in MacCMS Pro up to version 2022.1000.3005 involves an authorization bypass in the Installation Module's step5 function located in application/install/controller/Index.php. The flaw allows remote attackers to bypass authorization mechanisms, potentially gaining unauthorized access or privileges. Exploitation requires a high level of complexity and is difficult. The vulnerability has a CVSS 4.0 base score of 6.3 (medium severity). Upgrading to version 2022.1000.3025 is recommended to remediate the issue.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to bypass authorization controls remotely, potentially leading to unauthorized actions within the affected component. However, the attack complexity is high and exploitability is difficult, which may limit widespread exploitation.
Mitigation Recommendations
Upgrading MacCMS Pro to version 2022.1000.3025 is recommended to address this authorization bypass vulnerability. Patch status is confirmed by the recommendation to upgrade to this fixed version. No other mitigation guidance is provided.
CVE-2026-15516: Authorization Bypass in MacCMS Pro
Description
A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit is now public and may be used. Upgrading to version 2022.1000.3025 is recommended to address this issue. Upgrading the affected component is recommended.
CVSS v4.0
Score 6.3medium
Affected software
pkg:github/magicblack/maccms10cpe:2.3:a:maccms_pro:maccms_pro:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in MacCMS Pro up to version 2022.1000.3005 involves an authorization bypass in the Installation Module's step5 function located in application/install/controller/Index.php. The flaw allows remote attackers to bypass authorization mechanisms, potentially gaining unauthorized access or privileges. Exploitation requires a high level of complexity and is difficult. The vulnerability has a CVSS 4.0 base score of 6.3 (medium severity). Upgrading to version 2022.1000.3025 is recommended to remediate the issue.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to bypass authorization controls remotely, potentially leading to unauthorized actions within the affected component. However, the attack complexity is high and exploitability is difficult, which may limit widespread exploitation.
Mitigation Recommendations
Upgrading MacCMS Pro to version 2022.1000.3025 is recommended to address this authorization bypass vulnerability. Patch status is confirmed by the recommendation to upgrade to this fixed version. No other mitigation guidance is provided.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-07-12T11:05:41.518Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a54324268715ace43c2dac1
Added to database: 07/13/2026, 00:33:06 UTC
Last enriched: 07/13/2026, 00:47:39 UTC
Last updated: 08/24/2026, 22:52:09 UTC
Views: 105
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.