Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35173

24
FAUCET Score

OVERVIEW: CVE-2026-35173 is an Insecure Direct Object Reference (IDOR) and mass assignment vulnerability in Chyrp Lite blogging engine versions prior to 2026.01. The flaw resides in the Post model and permits authenticated users with standard post editing permissions to manipulate internal class properties through post_attributes payloads, thereby gaining unauthorized access to modify posts authored by other users, effectively achieving post takeover capabilities. SEVERITY: The vulnerability carries a CVSS 3.1 score of 6.5 (Medium) with an attack vector that is network-based, requires low complexity, and demands low privileges (authenticated access). The primary impact is high integrity compromise, as attackers can alter or take control of posts belonging to other users. Confidentiality and availability are not affected by this vulnerability. EXPLOITATION STATUS: Active exploitation appears unlikely at present. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and is not tracked on industry hot lists, indicating no current widespread exploitation. The EPSS score of 0.00026 reflects minimal real-world exploitation probability. However, organizations operating affected Chyrp Lite versions should prioritize patching to version 2026.01 or later to mitigate the risk of post takeover attacks by internal actors with editing permissions.

Impacted Technologies

VendorProductVersion(s)CPE
< 2026.01CPE matchmatch criteria
cpe:2.3:a:chyrplite:chyrp_lite:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
7.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 3rd percentile among its peer group of 21,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / xenocrat/chyrp-lite/security/advisories/GHSA-8c3h-rh2j-fxr9
Vendor Advisory