Junglewise Threat Intelligence

CVE-2026-84062: D-ZERO BurgerEditor authorization bypass through user-controlled key

CVE-2026-84062 · Severity: medium · CVSS 4.3 · Published 2026-09-10

Executive brief

BurgerEditor is a baserCMS plugin used to manage and update website content. An authenticated attacker with login credentials can bypass authorization checks by manipulating user identification information, allowing them to alter page content without proper permissions. This affects versions 3.0.0 through 3.4.0.

Technical details

This vulnerability is an authorization bypass (CWE-639) stemming from improper validation of user-controlled keys used in authorization checks. An attacker who can authenticate to the product can manipulate user identifier information to circumvent authorization controls and modify page content. The vulnerability requires valid login credentials (PR:L) and network accessibility (AV:N). No user interaction is required once authenticated. The vendor released patched versions (3.4.1 and 2.30.1) addressing the issue by implementing proper authorization validation.

Affected products

  • D-ZERO BurgerEditor 3.0.0 through 3.4.0

Timeline

  • 2026-09-09: disclosed
  • 2026-09-04: patched: Vendor released patched versions 3.4.1 and 2.30.1

References