CVE-2026-76909 | Unleash up to 8.0.2 Email Template requested-cr-approval.html.mustache sendRequestedCRApprovalEmail changeRequestTitle/requesterName/requesterEmail injection (EUVD-2026-84824)
A vulnerability was found in Unleash up to 8.0.2. It has been rated as problematic. The impacted element is the function sendRequestedCRApprovalEmail of the file src/mailtemplates/requested-cr-approval/requested-cr-approval.html.mustache of the component Email Template. Performing a manipulation of the argument changeRequestTitle/requesterName/requesterEmail results in injection.
This vulnerability was named CVE-2026-76909. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.