{"apiVersion":"1.0","identifier":"CVE-2026-43621","description":"Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gain administrator access by supplying multiple values for the user parameter. Attackers can exploit the mismatch between Profile::$member and User::$me->is_owner during sequential profile loading to be treated as the owner of an administrator profile, enabling unauthorized password changes and full account takeover.","publishedAt":"2026-08-26T22:16:24","lastModifiedAt":"2026-08-28T16:18:01","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-43621","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","epssProbability":0.00181,"riskScore":0.82,"affectedProduct":"Simple Machines Forum","affectedVersions":"<=2.1.7","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-43621","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-43621","en":"https://www.redsauce.net/en/cves/CVE-2026-43621","fr":"https://www.redsauce.net/fr/cves/CVE-2026-43621","pt":"https://www.redsauce.net/pt/cves/CVE-2026-43621","de":"https://www.redsauce.net/de/cves/CVE-2026-43621","sk":"https://www.redsauce.net/sk/cves/CVE-2026-43621","el":"https://www.redsauce.net/el/cves/CVE-2026-43621"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-43621"}}