← back
CVE-2026-21429

Emlog has Broken Access Control (BAC)

CVSS 2 LOWEPSS 0.2%CWE-862
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 2EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
02 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Emlog is an open source website building system. In version 2.5.23, the admin can set controls which makes users unable to edit or delete their articles after publishing them. As of time of publication, no known patched versions are available.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
emlog · emlog

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →