---
id: CVE-2026-84062
title: >-
  BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass
  through user-controlled key
summary: >-
  BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass
  through user-controlled key. If this vulnerability is exploited, the content
  of the page may be altered by an attacker who can log in to the product may be
  caused.
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-639
vendor: 'D-ZERO CO.,LTD.'
product: BurgerEditor
affected:
  - BurgerEditor 3.0.0 through 3.4.0
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T17:43:49.596319Z'
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T17:44:36.414Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-84062'
references:
  - url: 'https://jvn.jp/en/jp/JVN21088484/'
  - url: 'https://burger.d-zero.co.jp/blogs/archives/3'
tags:
  - cve.org
epss: 0.00297
epssPercentile: 0.19947
ingestedAt: '2026-09-11T14:42:19.865Z'
---

## Overview

BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key. If this vulnerability is exploited, the content of the page may be altered by an attacker who can log in to the product may be caused.

## Affected

- `BurgerEditor 3.0.0 through 3.4.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
