{"dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": {"cveId": "CVE-2026-96772", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2026-09-23T16:11:32.877Z", "datePublished": "2026-09-24T00:30:09.482Z", "dateUpdated": "2026-09-24T00:30:09.482Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2026-09-24T00:30:09.482Z"}, "title": "Intelliants Subrion CMS actions.json assign-owner information disclosure", "problemTypes": [{"descriptions": [{"type": "CWE", "cweId": "CWE-200", "lang": "en", "description": "Information Disclosure"}]}, {"descriptions": [{"type": "CWE", "cweId": "CWE-284", "lang": "en", "description": "Improper Access Controls"}]}], "affected": [{"vendor": "Intelliants", "product": "Subrion CMS", "versions": [{"version": "4.2.0", "status": "affected"}, {"version": "4.2.1", "status": "affected"}], "cpes": ["cpe:2.3:a:intelliants:subrion_cms:*:*:*:*:*:*:*:*"]}], "descriptions": [{"lang": "en", "value": "A security flaw has been discovered in Intelliants Subrion CMS up to 4.2.1. This affects an unknown part of the file /actions.json?action=assign-owner. The manipulation of the argument q results in information disclosure. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way."}], "metrics": [{"cvssV4_0": {"version": "4.0", "baseScore": 6.9, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P", "baseSeverity": "MEDIUM"}}, {"cvssV3_1": {"version": "3.1", "baseScore": 5.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R", "baseSeverity": "MEDIUM"}}, {"cvssV3_0": {"version": "3.0", "baseScore": 5.3, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R", "baseSeverity": "MEDIUM"}}, {"cvssV2_0": {"version": "2.0", "baseScore": 5, "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"}}], "timeline": [{"time": "2026-09-23T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed"}, {"time": "2026-09-23T02:00:00.000Z", "lang": "en", "value": "VulDB entry created"}, {"time": "2026-09-23T18:16:43.000Z", "lang": "en", "value": "VulDB entry last update"}], "credits": [{"lang": "en", "value": "volksec (VulDB User)", "type": "reporter"}, {"lang": "en", "value": "VulDB CNA Team", "type": "coordinator"}], "references": [{"url": "https://vuldb.com/vuln/409027", "name": "VDB-409027 | Intelliants Subrion CMS actions.json assign-owner information disclosure", "tags": ["vdb-entry", "technical-description"]}, {"url": "https://vuldb.com/vuln/409027/cti", "name": "VDB-409027 | CTI Indicators (IOB, IOC, TTP, IOA)", "tags": ["signature", "permissions-required"]}, {"url": "https://vuldb.com/cve/CVE-2026-96772", "name": "CVE-2026-96772 | CVE Analysis and Report", "tags": ["third-party-advisory"]}, {"url": "https://vuldb.com/submit/904804", "name": "Submit #904804 | Intelliants Subrion CMS 4.2.1 Information Disclosure", "tags": ["third-party-advisory"]}, {"url": "https://github.com/volksec/SubrionCMS-Security-Advisories/issues/1", "tags": ["exploit", "issue-tracking"]}], "tags": ["x_open-source"], "x_generator": ["VulDB PVTS v202609"]}}}