craftcms/cms Security Advisories for 5.9.0-beta.1 (1)
-
[HIGH] Craft CMS has unauthenticated activation email trigger with potential user enumeration
PKSA-s2xd-twzp-9yz7 CVE-2026-29069 GHSA-234q-vvw3-mrfq
Affected version: >=4.0.0-RC1,<4.17.0-beta.2|>=5.0.0-RC1,<5.9.0-beta.2
Reported by:
GitHub