CVE-2025-70866 Details
Description
LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in through /admin/login. The vulnerability exists because the admin and user authentication guards share the same user provider without role-based access control verification.
A vulnerability in LavaLite CMS version 10.1.0 allows authenticated users with low-level privileges to access the admin backend. This issue arises from incorrect access control, as the authentication guards for admin and user roles share the same user provider without proper role-based verification. As a result, users with the 'User' role can log in through the standard admin login route and gain unauthorized access to administrative features.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/gkjzjh146/6d541c80b0666a596581ccd85bd10058 | [email protected] | ExploitThird Party Advisory |
| https://github.com/LavaLite/cms/releases/tag/v10.1.0 | [email protected] | ProductRelease Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| lavalite lavalite | 10.1.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 19, 2026 | Initial Analysis | [email protected] |
| Feb 17, 2026 | CVE Modified | CISA-ADP |
| Feb 13, 2026 | New CVE Received | [email protected] |