A vulnerability described as critical has been identified in opensource-workshop connect-cms up to 1.41.0/2.41.0. This impacts an unknown function. Such manipulation leads to improper access controls.

This vulnerability is listed as CVE-2026-32299. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.