What is CVE-2026-63301?
CVE-2026-63301 is a vulnerability in Quick.CMS where the admin UI hides the option to delete the primary language, but the deletion API endpoint lacks server-side authorization, allowing an authenticated admin to delete it. This can lead to the loss of the site's primary language configuration. Users should apply the vendor's security patch or temporarily restrict access to the API endpoint.
Azərbaycanca: CVE-2026-63301, Quick.CMS-in idarəetmə panelində əsas dilin silinməsinin interfeysdə gizlədilməsinə baxmayaraq, API sorğusunda server tərəfində avtorizasiya yoxlanışı aparılmadığı üçün autentifikasiya olunmuş adminin əsas dili silə bilməsi zəifliyidir. Bu, saytın əsas dil konfiqurasiyasının itirilməsinə səbəb ola bilər. Quick.CMS istifadəçiləri tərtibatçının təqdim edəcəyi təhlükəsizlik yeniləməsini tətbiq etməli və ya müvəqqəti olaraq API-ə girişi məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
What operation does the CVE-2026-63301 vulnerability allow in Quick.CMS?
CVE-2026-63301 is a vulnerability that allows an authenticated admin to delete the primary language in Quick.CMS, even though the option is hidden in the UI, because the API endpoint lacks server-side authorization checks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.