CVE-2025-70866

LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in through /admin/login. The vulnerability exists because the admin and user authentication guards share the same user provider without role-based access control verification.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:lavalite:lavalite:10.1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-13 22:16

Updated : 2026-06-17 10:03


NVD link : CVE-2025-70866

Mitre link : CVE-2025-70866

CVE.ORG link : CVE-2025-70866


JSON object : View

Products Affected

lavalite

  • lavalite
CWE
CWE-284

Improper Access Control