THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5c4f-9pq9-6c77 (medium) — Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads

[GHSA] GHSA-5c4f-9pq9-6c77 (medium) — Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads

medgithub_advisoriesPublished 2026-08-12

GHSA-5c4f-9pq9-6c77 Severity: medium CVE: CVE-2026-32639

Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads

### Impact

Affected versions of Winter CMS did not enforce per-template-type permission checks in the CMS section's AJAX handlers. The CMS controller (`Cms\Controllers\Index`) used OR-logic across its five permissions (`cm

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5c4f-9pq9-6c77