THREAT OPS › Threat News › [GHSA] GHSA-5c4f-9pq9-6c77 (medium) — Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads
[GHSA] GHSA-5c4f-9pq9-6c77 (medium) — Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads
GHSA-5c4f-9pq9-6c77 Severity: medium CVE: CVE-2026-32639
Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads
### Impact
Affected versions of Winter CMS did not enforce per-template-type permission checks in the CMS section's AJAX handlers. The CMS controller (`Cms\Controllers\Index`) used OR-logic across its five permissions (`cm
Indicators of compromise
- CVE-2026-32639cve
Original source: https://github.com/advisories/GHSA-5c4f-9pq9-6c77