{"id":"CVE-2026-84062","title":"BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key","summary":"BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key. If this vulnerability is exploited, the content of the page may be altered by an attacker who can log in to the product may be caused.","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cvssSource":"cna","cwe":["CWE-639"],"vendor":"D-ZERO CO.,LTD.","product":"BurgerEditor","affected":["BurgerEditor 3.0.0 through 3.4.0"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-10T17:43:49.596319Z"},"published":"2026-09-10","updated":"2026-09-10","sourceUpdated":"2026-09-10T17:44:36.414Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-84062","references":[{"url":"https://jvn.jp/en/jp/JVN21088484/"},{"url":"https://burger.d-zero.co.jp/blogs/archives/3"}],"tags":["cve.org"],"epss":0.00297,"epssPercentile":0.22593,"ingestedAt":"2026-09-11T14:42:19.865Z","slug":"CVE-2026-84062","body":"## Overview\n\nBurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key. If this vulnerability is exploited, the content of the page may be altered by an attacker who can log in to the product may be caused.\n\n## Affected\n\n- `BurgerEditor 3.0.0 through 3.4.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}