Formie: Missing authorization on sent notification resend modal exposes submission PII
Summary
| CVE | CVE-2026-76089 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-23 19:19:14 UTC |
| Updated | 2026-09-23 20:17:14 UTC |
| Description | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs and read recipient headers and complete HTML email bodies containing submitted form data, even without the sent-notification viewing permission. This issue is fixed in versions 2.2.23 and 3.1.31. |
Risk And Classification
Primary CVSS: v3.1 7.7 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS: 0.002380000 probability, percentile 0.132210000 (date 2026-09-24)
Problem Types: CWE-200 | CWE-639 | CWE-862 | CWE-200 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | CWE-639 CWE-639: Authorization Bypass Through User-Controlled Key | CWE-862 CWE-862: Missing Authorization
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.7 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
| 3.1 | CNA | DECLARED | 7.7 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/verbb/formie/releases/tag/3.1.31 | [email protected] | github.com | |
| github.com/verbb/formie/commit/9f4e23c36b907ed7677563231eaba373fdb8b84b | [email protected] | github.com | |
| github.com/verbb/formie/security/advisories/GHSA-9rg8-2wvr-fgjh | [email protected] | github.com | |
| github.com/verbb/formie/releases/tag/2.2.23 | [email protected] | github.com | |
| github.com/verbb/formie/commit/ff81a895fa91a2e4efb8d4714501ba2d92df0b76 | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.