OVERVIEW: CVE-2026-35173 is an Insecure Direct Object Reference (IDOR) and mass assignment vulnerability in Chyrp Lite blogging engine versions prior to 2026.01. The flaw resides in the Post model and permits authenticated users with standard post editing permissions to manipulate internal class properties through post_attributes payloads, thereby gaining unauthorized access to modify posts authored by other users, effectively achieving post takeover capabilities. SEVERITY: The vulnerability carries a CVSS 3.1 score of 6.5 (Medium) with an attack vector that is network-based, requires low complexity, and demands low privileges (authenticated access). The primary impact is high integrity compromise, as attackers can alter or take control of posts belonging to other users. Confidentiality and availability are not affected by this vulnerability. EXPLOITATION STATUS: Active exploitation appears unlikely at present. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and is not tracked on industry hot lists, indicating no current widespread exploitation. The EPSS score of 0.00026 reflects minimal real-world exploitation probability. However, organizations operating affected Chyrp Lite versions should prioritize patching to version 2026.01 or later to mitigate the risk of post takeover attacks by internal actors with editing permissions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026.01CPE matchmatch criteria | cpe:2.3:a:chyrplite:chyrp_lite:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.