Junglewise Threat Intelligence

CVE-2026-29597: DDSN Interactive cm3 Acora CMS improper access control in file_details.asp

CVE-2026-29597 · Severity: medium · CVSS 6.5 · Published 2026-03-30

Technologies: DDSN Interactive Acora CMS. Vendors: DDSN Interactive.

Executive brief

DDSN Interactive cm3 Acora CMS, a content management system used for website administration, contains a security flaw that allows users with basic 'editor' permissions to access restricted system files. By accessing a specific administrative page and changing file parameters, an attacker can steal sensitive information including administrator passwords, database credentials, and email server settings. This could lead to a total takeover of the website, unauthorized access to corporate email, and potential theft of customer data stored in the backend database.

Technical details

An improper access control vulnerability exists in the '/Admin/file_manager/file_details.asp' endpoint of DDSN Interactive cm3 Acora CMS version 10.7.1. The flaw is triggered by manipulating the 'file' parameter via force browsing, which fails to properly validate the user's authorization level for specific system files. An authenticated attacker with 'editor' privileges can exploit this to read sensitive XML configuration files (such as cm3.xml). Successful exploitation allows the retrieval of plaintext system administrator credentials, SMTP settings, and database connection strings, facilitating full administrative takeover and lateral movement.

Affected products

  • DDSN Interactive cm3 Acora CMS 10.7.1

Timeline

  • 2026-03-30: advisory: Initial disclosure of CVE-2026-29597

References

Related threats