CVE-2026-86183 | diem-project diem up to 5.1.3 dmWidget BasedmWidgetActions.class.php widget_id authorization (Issue 450)
A vulnerability was found in diem-project diem up to 5.1.3. It has been declared as problematic. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation of the argument widget_id leads to authorization bypass.
This vulnerability is traded as CVE-2026-86183. The attack may be launched remotely. Furthermore, there is an exploit available.
A patch should be applied to remediate this issue.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More