A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation of the argument widget_id leads to authorization bypass. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is 116974edfb9a5b8bd69cb13586dc62bcdbb485ad. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet.
{
"cwe_ids": [
"CWE-285",
"CWE-639"
],
"cna_assigner": "VulDB",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86183.json"
}{
"extracted_events": [
{
"introduced": "5.1.0"
},
{
"last_affected": "5.1.0"
},
{
"introduced": "5.1.1"
},
{
"last_affected": "5.1.1"
},
{
"introduced": "5.1.2"
},
{
"last_affected": "5.1.2"
},
{
"introduced": "5.1.3"
},
{
"last_affected": "5.1.3"
}
],
"source": "AFFECTED_FIELD"
}