CVE-2026-29597: n/a
DDSN Interactive cm3 Acora CMS version 10.7.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive configuration files by force browsing the “/Admin/file_manager/file_details.asp” endpoint and manipulating the “file” parameter. By referencing specific files (e.g., cm3.xml), the attacker can retrieve system administrator credentials, SMTP settings, database credentials, and other confidential information. The exposure of this information can lead to full administrative access to the CMS, unauthorized access to email services, compromise of backend databases, lateral movement within the network, and long-term persistence by an attacker. This access control bypass poses a critical risk of account takeover, privilege escalation, and systemic compromise of the affected application and its associated infrastructure.
AI Analysis
Technical Summary
CVE-2026-29597 describes an improper access control vulnerability in DDSN Interactive cm3 Acora CMS version 10.7.1. An attacker with editor privileges can bypass intended restrictions by force browsing the /Admin/file_manager/file_details.asp endpoint and manipulating the file parameter to retrieve sensitive configuration files such as cm3.xml. The exposed information includes system administrator credentials, SMTP settings, and database credentials, which can be leveraged for privilege escalation, account takeover, and broader system compromise. This vulnerability is classified under CWE-284 (Improper Access Control) and has a CVSS 3.1 base score of 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). No patch or official remediation has been provided yet, and no known exploits are reported in the wild.
Potential Impact
The vulnerability allows an editor-privileged user to access sensitive configuration files containing credentials and settings critical to system security. Exposure of these details can lead to full administrative control of the CMS, unauthorized access to email services, compromise of backend databases, lateral movement within the network, and persistent attacker presence. Although the vulnerability requires editor-level privileges, the impact on confidentiality is high, while integrity and availability are not directly affected according to the CVSS vector.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, restrict editor privileges to trusted users only and monitor for suspicious activity involving the /Admin/file_manager/file_details.asp endpoint. Consider implementing additional access controls or web application firewall rules to block unauthorized file parameter manipulation targeting this endpoint.
CVE-2026-29597: n/a
Description
DDSN Interactive cm3 Acora CMS version 10.7.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive configuration files by force browsing the “/Admin/file_manager/file_details.asp” endpoint and manipulating the “file” parameter. By referencing specific files (e.g., cm3.xml), the attacker can retrieve system administrator credentials, SMTP settings, database credentials, and other confidential information. The exposure of this information can lead to full administrative access to the CMS, unauthorized access to email services, compromise of backend databases, lateral movement within the network, and long-term persistence by an attacker. This access control bypass poses a critical risk of account takeover, privilege escalation, and systemic compromise of the affected application and its associated infrastructure.
CVSS v3.1
Score 6.5medium
Affected software
pkg:github/padayali-jd/CVE-2026-29597Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-29597 describes an improper access control vulnerability in DDSN Interactive cm3 Acora CMS version 10.7.1. An attacker with editor privileges can bypass intended restrictions by force browsing the /Admin/file_manager/file_details.asp endpoint and manipulating the file parameter to retrieve sensitive configuration files such as cm3.xml. The exposed information includes system administrator credentials, SMTP settings, and database credentials, which can be leveraged for privilege escalation, account takeover, and broader system compromise. This vulnerability is classified under CWE-284 (Improper Access Control) and has a CVSS 3.1 base score of 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). No patch or official remediation has been provided yet, and no known exploits are reported in the wild.
Potential Impact
The vulnerability allows an editor-privileged user to access sensitive configuration files containing credentials and settings critical to system security. Exposure of these details can lead to full administrative control of the CMS, unauthorized access to email services, compromise of backend databases, lateral movement within the network, and persistent attacker presence. Although the vulnerability requires editor-level privileges, the impact on confidentiality is high, while integrity and availability are not directly affected according to the CVSS vector.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, restrict editor privileges to trusted users only and monitor for suspicious activity involving the /Admin/file_manager/file_details.asp endpoint. Consider implementing additional access controls or web application firewall rules to block unauthorized file parameter manipulation targeting this endpoint.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-03-04T00:00:00.000Z
- Cvss Version
- null
- State
- PUBLISHED
Threat ID: 69ca9c6fe6bfc5ba1d472599
Added to database: 03/30/2026, 15:53:19 UTC
Last enriched: 07/05/2026, 21:08:59 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 95
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.