Junglewise Threat Intelligence

CVE-2026-30452: Textpattern CMS broken access control in article management

CVE-2026-30452 · Severity: medium · CVSS 6.5 · Published 2026-04-21

Technologies: Textpattern CMS. Vendors: Textpattern.

Executive brief

Textpattern CMS, a platform used for building and managing websites, contains a security flaw in its article management system. This vulnerability allows a logged-in user with low-level permissions to modify or overwrite articles created by administrators or other high-privileged users. This could lead to unauthorized content changes, website defacement, or the loss of important editorial data.

Technical details

A broken access control vulnerability exists in Textpattern CMS 4.9.0 within the article management workflow. The flaw is located in 'textpattern/include/txp_article.php' and stems from an improper authorization check during the 'duplicate-and-save' process. By manipulating the article ID parameter in a web request, an authenticated attacker with low-level privileges can bypass ownership restrictions to overwrite content belonging to other users, including those with higher administrative roles. This issue was identified as a regression in version 4.9.0 and has been resolved in version 4.9.1.

Affected products

  • Textpattern Textpattern CMS 4.9.0

Timeline

  • 2026-02-14: patched: Textpattern 4.9.1 released to address the access control regression.
  • 2026-04-21: disclosed: CVE-2026-30452 published.

References

Related threats