A vulnerability, which was classified as problematic , was found in Sanluan PublicCMS 5.202506.d . This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/trade/TradeAddressListDirective.java of the component Trade Address Query Handler . Executing a manipulation of the argument userId/id can lead to missing authentication. The identification of this vulnerability is CVE-2026-8737 . The attack may be launched remotely. Furthermore, there is