


Perceptive Security
SOC/SIEM Consultancy

A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enfor…
Published:
2 september 2026 om 00:00:00
Alert date:
2 september 2026 om 22:04:04
Source:
nvd.nist.gov
Web Technologies, Identity & Access
A security vulnerability (CVE-2026-84841) has been identified in tsi-coop tsi-dpdp-cms versions up to 0.5.0. The flaw involves client-side enforcement of server-side security, meaning authentication or access controls are only enforced on the client side and can be bypassed by directly sending HTTP requests to the server. The vulnerability can be exploited remotely without requiring physical access. A public exploit has already been released, increasing the risk of active exploitation. The affected product is a CMS (Content Management System) developed by tsi-coop. Users are strongly advised to upgrade to version 0.5.1, which contains the security fix. The vulnerability falls under the CWE category of improper enforcement of behavioral workflow or client-side security controls. No workaround is mentioned other than upgrading to the patched version.
Technical details
Mitigation steps:
Affected products:
tsi-coop tsi-dpdp-cms up to 0.5.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-84841
https://github.com/mano257200/TSI-DPDP-CMS-Client-Side-Only-Authentication-Allows-Complete-Bypass-via-Direct-HTTP-Request/blob/main/README.md
https://github.com/tsi-coop/tsi-dpdp-cms/
https://github.com/tsi-coop/tsi-dpdp-cms/blob/main/docs/security-fixes/1.md
https://github.com/tsi-coop/tsi-dpdp-cms/releases/tag/v0.5.1
https://vuldb.com/cve/CVE-2026-84841
https://vuldb.com/submit/885661
https://vuldb.com/vuln/398083
https://vuldb.com/vuln/398083/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
