PKSA-c1gj-84dj-vvh3 Security Advisory
-
[MEDIUM] Craft CMS has Permission Bypass and IDOR in Duplicate Entry Action
PKSA-c1gj-84dj-vvh3 CVE-2026-28782 GHSA-jxm3-pmm2-9gf6
Affected package: craftcms/cms
Affected version: >=4.0.0-RC1,<4.17.0-beta.1|>=5.0.0-RC1,<5.9.0-beta.1
Reported by:
GitHub