CVE-2026-86183 Details
Description
A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation of the argument widget_id leads to authorization bypass. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is 116974edfb9a5b8bd69cb13586dc62bcdbb485ad. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet.
An authorization bypass vulnerability has been identified in the Diem content management framework, specifically in versions through 5.1.3. The issue resides in the dmFrontPlugin, within the dmWidget module, particularly in the BasedmWidgetActions.class.php file. The vulnerability allows remote exploitation by manipulating the widget_id argument, bypassing access controls for pages that own the selected widgets. This could lead to unauthorized access to content from protected or inactive pages.
Users are advised to apply the patch available in the Diem GitHub repository, which addresses this vulnerability by adding the necessary authorization checks. The patch can be found in the commit titled 'Passed catalog argument in I18N task'.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 6, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/diem-project/diem/ | [email protected] | Vendor |
| https://github.com/diem-project/diem/issues/450 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-86183 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/896155 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/399315 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/399315/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| diem-project diem | <= 5.1.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | CISA-ADP |
| Sep 6, 2026 | New CVE Received | [email protected] |
Volerion