CVE-2026-31867 | Craft CMS up to 4.10.x/5.5.x authorization (GHSA-vff3-pqq8-4cpq)
A vulnerability categorized as problematic has been discovered in Craft CMS up to 4.10.x/5.5.x. This affects an unknown function. Executing a manipulation can lead to authorization bypass.
This vulnerability is tracked as CVE-2026-31867. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.