CVE-2026-86183
A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation of the argument widget_id leads to authorization bypass. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is 116974edfb9a5b8bd69cb13586dc62bcdbb485ad. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.33%
- CWE
- CWE-639, CWE-285
- Published
- 2026-09-06
- Last modified
- 2026-09-06
Affected products
- diem-project diem
- diem-project diem
- diem-project diem
- diem-project diem
Weakness type
Related vulnerabilities
- CVE-2026-80354 — Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace
- CVE-2026-82582 — An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may...
- CVE-2026-84062 — BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through...
- CVE-2026-87997 — Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
- CVE-2026-87994 — Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
- CVE-2026-47156 — MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator
- CVE-2026-67403 — Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API....
- CVE-2026-86763 — snipe-it 7.0.12 through 8.6.3 Authorization Bypass via Importer