CVE Database
/

CVE-2026-28696

Back to search

CVE-2026-28696

Published: Mar 4, 2026

Modified: Mar 4, 2026

PUBLISHED

Description

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal reference tags (e.g., {user:1:email}), can be abused by both authenticated users and unauthenticated guests (if a Public Schema is enabled) to access sensitive attributes of any element in the CMS. The implementation in Elements::parseRefs fails to perform authorization checks, allowing attackers to read data they are not authorized to view. This vulnerability is fixed in 4.17.0-beta.1 and 5.9.0-beta.1.

VendorProductVersions

craftcms

cms

affected
>= 4.0.0-RC1, < 4.17.0-beta.1
affected
>= 5.0.0-RC1, < 5.9.0-beta.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now