Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐘 Packagist
Not in CISA KEV

CVE-2026-47266 — formie

CVE-2026-47266 is a CWE-639 vulnerability in verbb/formie. A fix is available for verbb/formie — see the affected versions and patch details below.

Formie: Unauthenticated front-end submission editing can overwrite existing submissions

Also known asGHSA-pgxq-p76c-x9cg
Published
Updated
Affected
2 pkgs
Patched
2 / 2
Exploits
None indexed
Exploitation data as of Oct 7, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-47266.

EPSS Exploitation Probability

via FIRST.org ↗
0.5%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs41th percentile — riskier than 41% of all scored CVEsHighest risk
0.00%0.33%0.66%1.00%0.0%0.5%Jun 26Sep 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Real-World Exposure

2 pkgs affected
🐘verbb/formie🐘verbb/formie

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.

Description

Impact

Unauthenticated users could modify existing submissions by posting a known or guessed submission ID to formie/submissions/save-submission.

Patches

2.2.21, 3.1.26

Workarounds

Block unauthenticated access to actions/formie/submissions/save-submission, or disable/customize front-end submission editing until patched.

Credit

formie extends many thanks to:

Affected Packages

2 total 2 fixed
EcosystemPackageVulnerable rangeFix
🐘Packagistverbb/formie≥ 3.0.0&&< 3.1.263.1.26composer require verbb/formie:^3.1.26
🐘Packagistverbb/formieall versions2.2.21composer require verbb/formie:^2.2.21

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for verbb/formie, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update verbb/formie to 3.1.26 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-47266 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

Frequently Asked Questions

### Impact Unauthenticated users could modify existing submissions by posting a known or guessed submission ID to `formie/submissions/save-submission`. ### Patches [2.2.21](https://github.com/verbb/formie/releases/tag/2.2.21), [3.1.26](https://github.com/verbb/formie/releases/tag/3.1.26) ### Workarounds Block unauthenticated access to `actions/formie/submissions/save-submission`, or disable/customize front-end submission editing until patched. ### Credit formie extends many thanks to: - Florian (Cyber Security Engineer, arcade solutions ag) - Contact: [[email protected]](mailto:security@ar
O3 Security · Impact-Aware SCA

Is CVE-2026-47266 in your dependencies?

Find it across Packagist, including transitive dependencies.

CVE-2026-47266: formie — Fixed in 3.1.26