CVE-2024-36042: Silverpeas

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.

Affected products

  • Silverpeas Silverpeas: before 6.3.5 (fixed in 6.3.5)

Published 2024-06-03. Last modified 2026-06-17.