Vulnerability Description
When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if the user creating the export does not have permission to view gift cards. This is inconsistent with the UI and API where only the first letters of the gift card secret are shown. Therefore, it allows circumventing a permission boundary.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-11764?
CVE-2026-11764 is a documented vulnerability. When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if the user creating the export does not have permission to view gift cards. This ...
How severe is CVE-2026-11764?
CVSS scoring is not yet available for CVE-2026-11764. Check NVD for updates.
Is there a patch for CVE-2026-11764?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.