A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of the file ujcms-cms/src/main/java/com/ujcms/cms/core/web/api/UserController.java of the component UserController. Performing a manipulation of the argument Username results in improper authorization. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.

Project Subscriptions

Vendors Products
Dromara Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 20 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Dromara
Dromara ujcms
Vendors & Products Dromara
Dromara ujcms

Sun, 20 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of the file ujcms-cms/src/main/java/com/ujcms/cms/core/web/api/UserController.java of the component UserController. Performing a manipulation of the argument Username results in improper authorization. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.
Title Dromara UJCMS UserController UserController.java usernameExist improper authorization
First Time appeared Ujcms
Ujcms ujcms
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:ujcms:ujcms:*:*:*:*:*:*:*:*
Vendors & Products Ujcms
Ujcms ujcms
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-20T04:45:09.620Z

Reserved: 2026-09-19T09:19:19.922Z

Link: CVE-2026-93961

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-20T05:16:28.093

Modified: 2026-09-20T05:16:28.093

Link: CVE-2026-93961

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:00:08Z

Weaknesses