top of page
perceptive_background_267k.jpg

A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enfor…

Published:

2 september 2026 om 00:00:00

Alert date:

2 september 2026 om 22:04:04

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

A security vulnerability (CVE-2026-84841) has been identified in tsi-coop tsi-dpdp-cms versions up to 0.5.0. The flaw involves client-side enforcement of server-side security, meaning authentication or access controls are only enforced on the client side and can be bypassed by directly sending HTTP requests to the server. The vulnerability can be exploited remotely without requiring physical access. A public exploit has already been released, increasing the risk of active exploitation. The affected product is a CMS (Content Management System) developed by tsi-coop. Users are strongly advised to upgrade to version 0.5.1, which contains the security fix. The vulnerability falls under the CWE category of improper enforcement of behavioral workflow or client-side security controls. No workaround is mentioned other than upgrading to the patched version.

Technical details

Mitigation steps:

Affected products:

tsi-coop tsi-dpdp-cms up to 0.5.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page