CVE-2026-84841 Details
Description
A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of server-side security. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.5.1 is able to resolve this issue. It is recommended to upgrade the affected component.
A vulnerability exists in TSI-Coop TSI-DPDP-CMS versions through 0.5.0, allowing client-side enforcement of server-side security. This issue arises because authentication is handled solely by browser-based JavaScript, which can be bypassed by direct HTTP requests from clients that do not execute JavaScript, such as curl or Python requests. As a result, unauthenticated users can access sensitive administrative and Data Protection Officer (DPO) console pages, including internal application logic and API endpoint information.
Upgrade to TSI-Coop TSI-DPDP-CMS version 0.5.1, which includes a server-side authentication gate for console pages, ensuring that valid credentials are required before access is granted.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 2, 2026CISA-ADP
Assessed Sep 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/mano257200/TSI-DPDP-CMS-Client-Side-Only-Authentication-Allows-Complete-Bypass-via-Direct-HTTP-Request/blob/main/README.md | [email protected] | ExploitTechnical Description |
| https://github.com/tsi-coop/tsi-dpdp-cms/ | [email protected] | ProductVendor |
| https://github.com/tsi-coop/tsi-dpdp-cms/blob/main/docs/security-fixes/1.md | [email protected] | Technical AnalysisVendor |
| https://github.com/tsi-coop/tsi-dpdp-cms/releases/tag/v0.5.1 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-84841 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/885661 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/398083 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/398083/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-602 | Client-Side Enforcement of Server-Side Security | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| tsi-coop tsi-dpdp-cms | <= 0.5.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 5, 2026 | CVE Modified | CISA-ADP |
| Sep 2, 2026 | New CVE Received | [email protected] |
Volerion