← Back to overview

A security vulnerability (CVE-2026-84841) has been identified in tsi-coop tsi-dpdp-cms versions up to 0.5.0. The flaw involves client-side enforcement of server-side security, meaning authentication or access controls are only enforced on the client side and can be bypassed by directly sending HTTP requests to the server. The vulnerability can be exploited remotely without requiring physical access. A public exploit has already been released, increasing the risk of active exploitation. The affected product is a CMS (Content Management System) developed by tsi-coop. Users are strongly advised to upgrade to version 0.5.1, which contains the security fix. The vulnerability falls under the CWE category of improper enforcement of behavioral workflow or client-side security controls. No workaround is mentioned other than upgrading to the patched version.

Affected products

  • tsi-coop tsi-dpdp-cms up to 0.5.0

Related CVE's

  • CVE-2026-84841

Categories

  • Identity & Access
  • Web Technologies