CVE-2026-39397 | delmaredigital payload-puck up to 0.6.22 CRUD Endpoint createPuckPlugin authorization (EUVD-2026-19921)
A vulnerability, which was classified as critical, has been found in delmaredigital payload-puck up to 0.6.22. This affects the function createPuckPlugin of the component CRUD Endpoint. This manipulation causes missing authorization.
This vulnerability is handled as CVE-2026-39397. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.