{"id":"CVE-2026-84841","summary":"tsi-coop tsi-dpdp-cms client-side enforcement of server-side security","details":"A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of server-side security. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.5.1 is able to resolve this issue. It is recommended to upgrade the affected component.","modified":"2026-09-06T08:00:48.628842Z","published":"2026-09-02T18:45:10.714Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-602"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84841.json"},"references":[{"type":"WEB","url":"https://github.com/tsi-coop/tsi-dpdp-cms/"},{"type":"WEB","url":"https://github.com/tsi-coop/tsi-dpdp-cms/blob/main/docs/security-fixes/1.md"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84841.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84841"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-84841"},{"type":"ADVISORY","url":"https://vuldb.com/submit/885661"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/398083"},{"type":"REPORT","url":"https://vuldb.com/vuln/398083/cti"},{"type":"FIX","url":"https://github.com/tsi-coop/tsi-dpdp-cms/releases/tag/v0.5.1"},{"type":"EVIDENCE","url":"https://github.com/mano257200/TSI-DPDP-CMS-Client-Side-Only-Authentication-Allows-Complete-Bypass-via-Direct-HTTP-Request/blob/main/README.md"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tsi-coop/tsi-dpdp-cms","events":[{"introduced":"c2c8732cf7abc8e093299fec015615bce6524043"},{"fixed":"18f35f04447872a3243b75b5a8aeaa1fd7239bef"}],"database_specific":{"extracted_events":[{"introduced":"0.1"},{"last_affected":"0.1"},{"introduced":"0.2"},{"last_affected":"0.2"},{"introduced":"0.3"},{"last_affected":"0.3"},{"introduced":"0.4"},{"last_affected":"0.4"},{"introduced":"0.5.0"},{"last_affected":"0.5.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["0.1","0.2","0.3","0.4","0.5.0","v0.5.0","v0.4.9","v0.4.8","v0.4.7","v0.4.6","v0.4.5","v0.4.4","v0.4.3","v0.4.2","v0.4.1","v0.4","v0.3","v0.2","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84841.json","vanir_signatures_modified":"2026-09-06T08:00:48Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/tsi-coop/tsi-dpdp-cms/commit/18f35f04447872a3243b75b5a8aeaa1fd7239bef","target":{"file":"src/org/tsicoop/dpdpcms/service/v1/AdminSetup.java"},"deprecated":false,"digest":{"line_hashes":["250472216722402734104061782355215519111","153515143207338275641410653895934773035","180614048942477380333626795275031769306","61778191575002692793210705736656462572","282269796761919970058660283271881534274","242639402441324601054616015366266054684","97956153476787394213694132196964340061","219101532630030447457509191542714540938","319332463195028898770369261630593076995","44557872028062078763778784495570543107","196218335496574331768596257037394660604","98398065208785670933147691124588261923","313679369130660551293440077035045957640","162124469803268952745358059571472066900","172468608257877802512527931760402118063","218350966992979505992395286075396186771","128003151044219072679611981512106381563","95260908930458339024692089559365831506","17717968067049525165987898077689208122","147986469541465501062514702993191623349","27440096732924321145083731353059044414","239802015861852721734850485192852252890","212845597264742464156419156857788404374","248718959639371394212277171601100420018","211506805339486380593034369393703143595","303986033984073245597258319862638396313","181295410957308451301983558760907521307","73850379356169208278266961016275074062","100389516977321388999224882846091797247"],"threshold":0.9},"id":"CVE-2026-84841-3edbe645","signature_type":"Line"},{"digest":{"function_hash":"170016251835083542850370707063958464017","length":2698},"id":"CVE-2026-84841-55829e31","signature_type":"Function","signature_version":"v1","source":"https://github.com/tsi-coop/tsi-dpdp-cms/commit/18f35f04447872a3243b75b5a8aeaa1fd7239bef","target":{"file":"src/org/tsicoop/dpdpcms/service/v1/Operator.java","function":"handleLogin"},"deprecated":false},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/tsi-coop/tsi-dpdp-cms/commit/18f35f04447872a3243b75b5a8aeaa1fd7239bef","target":{"file":"src/org/tsicoop/dpdpcms/service/v1/AdminSetup.java","function":"performInitialSetup"},"deprecated":false,"digest":{"function_hash":"339345187394699435555257903700973392745","length":624},"id":"CVE-2026-84841-632a42f2"},{"deprecated":false,"digest":{"line_hashes":["168144796550234577620461396633821165010","190479784715125092852073431253829443147","97133016112726292342217523854869350936"],"threshold":0.9},"id":"CVE-2026-84841-71296fb7","signature_type":"Line","signature_version":"v1","source":"https://github.com/tsi-coop/tsi-dpdp-cms/commit/18f35f04447872a3243b75b5a8aeaa1fd7239bef","target":{"file":"src/org/tsicoop/dpdpcms/framework/InputProcessor.java"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/tsi-coop/tsi-dpdp-cms/commit/18f35f04447872a3243b75b5a8aeaa1fd7239bef","target":{"file":"src/org/tsicoop/dpdpcms/service/v1/Operator.java","function":"handleLogout"},"deprecated":false,"digest":{"function_hash":"254499771655642101752609818917179779296","length":751},"id":"CVE-2026-84841-7bf6db81"},{"signature_version":"v1","source":"https://github.com/tsi-coop/tsi-dpdp-cms/commit/18f35f04447872a3243b75b5a8aeaa1fd7239bef","target":{"file":"src/org/tsicoop/dpdpcms/service/v1/AdminSetup.java","function":"post"},"deprecated":false,"digest":{"function_hash":"47764483691264100578833822551024191969","length":2071},"id":"CVE-2026-84841-957e81e4","signature_type":"Function"},{"digest":{"line_hashes":["54105518578364645003510450566180077590","315215604280527446040488662872011241977"],"threshold":0.9},"id":"CVE-2026-84841-97c0235b","signature_type":"Line","signature_version":"v1","source":"https://github.com/tsi-coop/tsi-dpdp-cms/commit/18f35f04447872a3243b75b5a8aeaa1fd7239bef","target":{"file":"src/org/tsicoop/dpdpcms/util/Constants.java"},"deprecated":false},{"source":"https://github.com/tsi-coop/tsi-dpdp-cms/commit/18f35f04447872a3243b75b5a8aeaa1fd7239bef","target":{"file":"src/org/tsicoop/dpdpcms/service/v1/Operator.java"},"deprecated":false,"digest":{"line_hashes":["81470657570310543048476049778456254968","167197765425960899165223372759656597541","19582413581543432790224381119387506264","146740561993377831685318827170744327560","76044978758252598220312339646365501598","191146923176190635191133456777986574041","70922012124940125287253867064884911925","203000558782833075064361349094631607427"],"threshold":0.9},"id":"CVE-2026-84841-a6bb2a79","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}