Executive brief
Pagekit CMS, a content management system, contains a security flaw that allows staff members with basic user-management permissions to grant themselves full administrative control. By elevating their own privileges, an attacker can upload malicious files to the server, leading to a complete takeover of the website and underlying server. This could result in the theft of sensitive data, website defacement, or the installation of ransomware.
Technical details
A privilege escalation vulnerability exists in Pagekit CMS 1.0.18 due to missing authorization checks in the `UserApiController::saveAction()` method. While the application explicitly blocks non-administrators from assigning the hard-coded 'Administrator' role (ID 3), it fails to validate the assignment of custom roles. An attacker with 'user: manage users' permissions can send a crafted POST request to `/api/user/{id}` to assign themselves a custom role containing the 'system: manage packages' permission. Once elevated, the attacker can use the admin package installer to upload and execute a malicious PHP package, resulting in full remote code execution (RCE). The project is currently archived and unmaintained.
Affected products
- Pagekit Pagekit CMS <= 1.0.18
Timeline
- 2026-06-26: disclosed: Vulnerability disclosed by Saidakbarxon Maqsudxonov
- 2026-06-26: advisory: CVE-2026-57518 published