{"id":"CVE-2026-28696","aliases":["GHSA-7x43-mpfg-r9wj"],"url":"https://o3.security/vulnerability/CVE-2026-28696","summary":"Craft affected by IDOR via GraphQL @parseRefs","details":"Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal reference tags (e.g., {user:1:email}), can be abused by both authenticated users and unauthenticated guests (if a Public Schema is enabled) to access sensitive attributes of any element in the CMS. The implementation in Elements::parseRefs fails to perform authorization checks, allowing attackers to read data they are not authorized to view. This vulnerability is fixed in 4.17.0-beta.1 and 5.9.0-beta.1.","published":"2026-03-04T16:21:43.199Z","modified":"2026-08-07T11:50:15.191118776Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"4.17.0-beta.1"},{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"5.9.0-beta.1"}],"fix":{"url":"https://github.com/craftcms/cms/commit/4d98a07e47580f1712095825d3e3c4d67bc9f8b9","label":"craftcms/cms@4d98a07"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28696.json"},{"type":"ADVISORY","url":"https://github.com/craftcms/cms/security/advisories/GHSA-7x43-mpfg-r9wj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28696"},{"type":"FIX","url":"https://github.com/craftcms/cms/commit/4d98a07e47580f1712095825d3e3c4d67bc9f8b9"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:50:15.191118776Z"}}