Junglewise Threat Intelligence

CVE-2026-75465: MacCMS v10 user list endpoint authentication bypass

CVE-2026-75465 · Severity: high · CVSS 7.5 · Published 2026-08-25

Executive brief

MacCMS v10 is a content management system for video streaming and media platforms. An unauthenticated attacker can retrieve a complete list of registered users including usernames, phone numbers, and registration timestamps by accessing an API endpoint that lacks access controls. This privacy breach could enable targeted phishing, credential harvesting, or harassment campaigns against users.

Technical details

The /api.php/user/get_list endpoint in MacCMS v10 v2026.1000.4055 is vulnerable to incorrect access control (CWE-284). The vulnerable component, application/api/controller/User.php, fails to enforce any authentication or authorization checks before returning user list data. An unauthenticated remote attacker can send a crafted GET request with limit and offset parameters to paginate through and retrieve sensitive information for all registered users. The attack requires no authentication, no special privileges, and is network-accessible; an attacker can retrieve unbounded user records including user IDs, usernames, phone numbers, and registration times. No vendor-fixed version has been confirmed as of publication.

Affected products

  • magicblack MacCMS v10 v2026.1000.4055

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: advisory

References