tsi-coop tsi-dpdp-cms Bootstrap Setup Endpoint InterceptingFilter.java missing authentication
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.9epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability was identified in tsi-coop tsi-dpdp-cms up to 0.5.0. This affects an unknown part of the file InterceptingFilter.java of the component Bootstrap Setup Endpoint. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used. Upgrading to version 0.5.1 is able to mitigate this issue. Upgrading the affected component is recommended.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
tsi-coop · tsi-dpdp-cmspublic PoCs found — 1
cve_referencegithub.com/mano257200/TSI-DPDP-CMS-Unauthenticated-Super-Admin-Bootstrap-Endpoint/blob/main/README.mdunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://github.com/mano257200/TSI-DPDP-CMS-Unauthenticated-Super-Admin-Bootstrap-Endpoint/blob/main/README.mdhttps://github.com/tsi-coop/tsi-dpdp-cms/https://github.com/tsi-coop/tsi-dpdp-cms/blob/main/docs/security-fixes/2.mdhttps://github.com/tsi-coop/tsi-dpdp-cms/releases/tag/v0.5.1https://vuldb.com/cve/CVE-2026-84840https://vuldb.com/submit/885658https://vuldb.com/vuln/398082https://vuldb.com/vuln/398082/cti