THREAT OPS › Threat News › [NVD] CVE-2026-32639 (MEDIUM 6.8) — Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type permission checks, allowing a backend user with any single CMS permission to act on
[NVD] CVE-2026-32639 (MEDIUM 6.8) — Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type permission checks, allowing a backend user with any single CMS permission to act on
CVE-2026-32639 CVSS: 6.8 MEDIUM Published: 2026-08-26T18:16:30.427
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type permission checks, allowing a backend user with any single CMS permission to act on template types outside their authorized scope. The
Indicators of compromise
- CVE-2026-32639cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-32639