THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-g2fm-8hr4-j82h (high) — EasyAdmin custom-action dispatcher bypasses access_control on other routes

[GHSA] GHSA-g2fm-8hr4-j82h (high) — EasyAdmin custom-action dispatcher bypasses access_control on other routes

medgithub_advisoriesPublished 2026-09-02

GHSA-g2fm-8hr4-j82h Severity: high CVE: CVE-2026-81892

EasyAdmin custom-action dispatcher bypasses access_control on other routes

## Summary

EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (`Action::linkToRoute()` / `MenuItem::linkToRoute()`), swaps the executed controller based on the `routeName` query parameter on the `kernel.controller` event.

Indicators of compromise

Original source: https://github.com/advisories/GHSA-g2fm-8hr4-j82h