GHSA-pgpf-m8m4-6cg6
CRITICALCVE-2026-27591Affected versions of Winter CMS allowed authenticated backend users to escalate their accounts level of access to the system by modifying the roles / permissions assigned to their account through specially crafted requests to the backend while logged in.
- Affected
- >= 1.2.0, < 1.2.12
- Fixed in
- 1.2.12
- Weakness
- CWE-284
- Published
- 2026-03-12
- Source
- github