Description
Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitrary custom roles to themselves due to missing authorization checks in UserApiController::saveAction(). Attackers can assign themselves a custom role with the 'system: manage packages' permission and then upload and install a malicious PHP package through the admin package installer to achieve remote code execution.
Severity (CVSS)
| Base score | 8.7 |
|---|---|
| Severity | High |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| Provided by | CNA |
Weaknesses
- CWE-862 — Missing Authorization
Affected products
| Vendor | Product | Versions |
|---|---|---|
| pagekit | pagekit | 0 to <=1.0.18 |
References
- https://gist.github.com/sermikr0/6f0a67e9d101746fcdb04827de137847 (technical-description exploit)
- https://www.vulncheck.com/advisories/pagekit-cms-privilege-escalation-via-userapicontroller (third-party-advisory)
Generated from the official CVE List on 27 Jun 2026 07:02 UTC.