THREAT OPS › Threat News › [GHSA] GHSA-g2fm-8hr4-j82h (high) — EasyAdmin custom-action dispatcher bypasses access_control on other routes
[GHSA] GHSA-g2fm-8hr4-j82h (high) — EasyAdmin custom-action dispatcher bypasses access_control on other routes
GHSA-g2fm-8hr4-j82h Severity: high CVE: CVE-2026-81892
EasyAdmin custom-action dispatcher bypasses access_control on other routes
## Summary
EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (`Action::linkToRoute()` / `MenuItem::linkToRoute()`), swaps the executed controller based on the `routeName` query parameter on the `kernel.controller` event.
Indicators of compromise
- CVE-2026-81892cve
Original source: https://github.com/advisories/GHSA-g2fm-8hr4-j82h