๐Ÿ” CVE Alert

CVE-2026-57518

HIGH 8.8

Pagekit CMS 1.0.18 Privilege Escalation via UserApiController

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitrary custom roles to themselves due to missing authorization checks in UserApiController::saveAction(). Attackers can assign themselves a custom role with the 'system: manage packages' permission and then upload and install a malicious PHP package through the admin package installer to achieve remote code execution.

CWE CWE-862
Vendor pagekit
Product pagekit
Published Jun 26, 2026
Stay Ahead of the Next One

Get instant alerts for pagekit pagekit

Be the first to know when new high vulnerabilities affecting pagekit pagekit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

pagekit / pagekit
0 โ‰ค 1.0.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gist.github.com: https://gist.github.com/sermikr0/6f0a67e9d101746fcdb04827de137847 vulncheck.com: https://www.vulncheck.com/advisories/pagekit-cms-privilege-escalation-via-userapicontroller

Credits

Saidakbarxon Maqsudxonov