{"id":"PYSEC-2026-839","summary":"Lin CMS vulnerable to Improper Authentication","details":"An authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator.","aliases":["CVE-2022-44244","GHSA-4vrc-q7m6-vq7w"],"modified":"2026-07-07T11:46:04.757162484Z","published":"2026-07-07T10:17:23.245195Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-44244"},{"type":"WEB","url":"https://gist.github.com/cai-niao98/58c97899695488bd73a73d56adf44c4c"},{"type":"PACKAGE","url":"https://github.com/TaleLin/lin-cms-flask"},{"type":"WEB","url":"https://github.com/cai-niao98/lin-cms"},{"type":"PACKAGE","url":"https://pypi.org/project/lin-cms"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4vrc-q7m6-vq7w"}],"affected":[{"package":{"name":"lin-cms","ecosystem":"PyPI","purl":"pkg:pypi/lin-cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.2.1"}]}],"versions":["0.1.1a1","0.1.1a2","0.1.1a3","0.1.1a4","0.1.1a5","0.1.1a6","0.1.1a7","0.1.1a8","0.1.1b1","0.1.1b2","0.1.1b3","0.1.1b4","0.2.0b1","0.2.0b2","0.2.0b3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/lin-cms/PYSEC-2026-839.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}