CVE-2026-57579 | AlchemyCMS Alchemy CMS up to 7.4.14/8.0.14/8.1.13/8.2.5 PageTreeSerializer pages_controller.rb PagesController#nested elements improper authorization

SecurityVulns

A vulnerability labeled as problematic has been found in AlchemyCMS Alchemy CMS up to 7.4.14/8.0.14/8.1.13/8.2.5. This issue affects the function Api::PagesController#nested of the file app/controllers/alchemy/api/pages_controller.rb of the component PageTreeSerializer. Such manipulation of the argument elements leads to improper authorization.

This vulnerability is documented as CVE-2026-57579. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More