NONE · 0

CVE-2026-46721

The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitra...

Vulnerability Description

The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-46721?

CVE-2026-46721 is a documented vulnerability. The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitra...

How severe is CVE-2026-46721?

CVSS scoring is not yet available for CVE-2026-46721. Check NVD for updates.

Is there a patch for CVE-2026-46721?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.