LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in through /admin/login. The vulnerability exists because the admin and user authentication guards share the same user provider without role-based access control verification.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in through /admin/login. The vulnerability exists because the admin and user authentication guards share the same user provider without role-based access control verification. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-13T21:27:59.032Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70866
No data.
Status : Received
Published: 2026-02-13T22:16:09.923
Modified: 2026-02-13T22:16:09.923
Link: CVE-2025-70866
No data.
OpenCVE Enrichment
No data.