Junglewise Threat Intelligence

CVE-2026-72601: CSZ CMS broken access control in form submission viewer

CVE-2026-72601 · Severity: high · CVSS 7.5 · Published 2026-08-11

Executive brief

CSZ CMS is a web-based content management system. A security flaw allows anyone on the internet to view all contact form submissions and their attached personal information (names, email addresses, phone numbers, etc.) without needing to log in. This means sensitive customer inquiries and data could be exposed to unauthorized parties.

Technical details

The vulnerability is a broken access control issue in the admin form-submission viewer endpoint of CSZ CMS 1.3.2. The endpoint fails to verify user authentication before serving form submission records, and the framework's authentication helper fails open. An unauthenticated remote attacker can directly access the viewer endpoint over the network to read all stored contact form submissions, including personally identifiable information (PII), without providing any credentials. No authentication bypass or user interaction is required.

Affected products

  • CSZ CSZ CMS 1.3.2

Timeline

  • 2026-08-11: disclosed

References