CVE-2026-96772 Details
Description
A security flaw has been discovered in Intelliants Subrion CMS up to 4.2.1. This affects an unknown part of the file /actions.json?action=assign-owner. The manipulation of the argument q results in information disclosure. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability allowing information disclosure has been identified in Intelliants Subrion CMS versions through 4.2.1. The issue arises in the 'assign-owner' action of the JSON API, where the 'q' parameter can be manipulated to leak data about active users. This vulnerability can be exploited remotely without authentication. The exposed information includes user IDs, full names, and email addresses, which could be used for targeted phishing or social engineering attacks.
It is recommended to require authentication and explicit permissions for the 'assign-owner' action. Additionally, the response should be limited to essential account details, excluding email addresses, and the application should implement measures to escape SQL wildcard characters in search queries.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026CISA-ADP
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/volksec/SubrionCMS-Security-Advisories/issues/1 | [email protected] | ExploitIssue TrackingTechnical Description |
| https://vuldb.com/cve/CVE-2026-96772 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/904804 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/409027 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/409027/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Intelliants Subrion CMS | <= 4.2.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | CVE Modified | CISA-ADP |
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion