CVE-2026-2010 is an improper authorization vulnerability affecting Sanluan PublicCMS versions up to 4.0.202506.d, 5.202506.d, and 6.202506.d. Specifically, the "Paid" function within the Trade Payment Handler component (TradePaymentService.java) allows remote attackers to manipulate the paymentId argument, leading to unauthorized actions. The vulnerability has a CVSS score of 4.2 (MEDIUM), indicating a network attack vector with high attack complexity, but only low impact on integrity and availability. While the attack can be initiated remotely, its exploitability is considered difficult. The exploit has been publicly disclosed, and a patch (7329437e1288540336b1c66c114ed3363adcba02) is available. There is currently no evidence of active exploitation, no known Metasploit or Nuclei modules, and no significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.0.202506.dCPE matchmatch criteria | cpe:2.3:a:publiccms:publiccms:*:*:*:*:*:*:*:* | ||
>= 5.202302.a, <= 5.202506.dCPE matchmatch criteria | cpe:2.3:a:publiccms:publiccms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.