Junglewise Threat Intelligence

CVE-2026-57518: Pagekit CMS privilege escalation in UserApiController

CVE-2026-57518 · Severity: high · CVSS 8.8 · Published 2026-06-26

Technologies: Pagekit CMS. Vendors: Pagekit.

Executive brief

Pagekit CMS, a content management system, contains a security flaw that allows staff members with basic user-management permissions to grant themselves full administrative control. By elevating their own privileges, an attacker can upload malicious files to the server, leading to a complete takeover of the website and underlying server. This could result in the theft of sensitive data, website defacement, or the installation of ransomware.

Technical details

A privilege escalation vulnerability exists in Pagekit CMS 1.0.18 due to missing authorization checks in the `UserApiController::saveAction()` method. While the application explicitly blocks non-administrators from assigning the hard-coded 'Administrator' role (ID 3), it fails to validate the assignment of custom roles. An attacker with 'user: manage users' permissions can send a crafted POST request to `/api/user/{id}` to assign themselves a custom role containing the 'system: manage packages' permission. Once elevated, the attacker can use the admin package installer to upload and execute a malicious PHP package, resulting in full remote code execution (RCE). The project is currently archived and unmaintained.

Affected products

  • Pagekit Pagekit CMS <= 1.0.18

Timeline

  • 2026-06-26: disclosed: Vulnerability disclosed by Saidakbarxon Maqsudxonov
  • 2026-06-26: advisory: CVE-2026-57518 published

References

Related threats