CVE-2026-29069 | Craft CMS prior 4.17.0-beta.2/5.9.0-beta.2 User Account actionSendActivationEmail authorization (GHSA-234q-vvw3-mrfq / EUVD-2026-9452)
A vulnerability marked as problematic has been reported in Craft CMS. Affected is the function actionSendActivationEmail of the component User Account Handler. Performing a manipulation results in authorization bypass.
This vulnerability is known as CVE-2026-29069. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.