A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the component UCenter Article Submission Endpoint. Executing a manipulation of the argument id/userId can lead to improper authorization. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
History

Tue, 26 May 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 24 May 2026 11:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the component UCenter Article Submission Endpoint. Executing a manipulation of the argument id/userId can lead to improper authorization. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Title JPress UCenter Article Submission Endpoint doWriteSave improper authorization
First Time appeared Jpress
Jpress jpress
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:jpress:jpress:*:*:*:*:*:*:*:*
Vendors & Products Jpress
Jpress jpress
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2026-05-24T10:45:07.960Z

Updated: 2026-05-26T14:33:11.869Z

Reserved: 2026-05-23T14:52:08.755Z

Link: CVE-2026-9376

cve-icon Vulnrichment

Updated: 2026-05-26T14:33:06.251Z

cve-icon NVD

Status : Deferred

Published: 2026-05-24T11:16:34.480

Modified: 2026-05-26T19:54:40.357

Link: CVE-2026-9376

cve-icon Redhat

No data.