THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fm29-4mq3-phg6 (medium) — Winter: ImportExportController AJAX handlers bypass granular import/export permission gate

[GHSA] GHSA-fm29-4mq3-phg6 (medium) — Winter: ImportExportController AJAX handlers bypass granular import/export permission gate

highgithub_advisoriesPublished 2026-08-20

GHSA-fm29-4mq3-phg6 Severity: medium CVE: None

Winter: ImportExportController AJAX handlers bypass granular import/export permission gate

### Impact

Affected versions of Winter CMS did not enforce the `ImportExportController` behavior's granular access control on the handlers that actually perform the work.

The behavior supports per-operation access control through the `import[permissions]` an

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fm29-4mq3-phg6