{"id":"CVE-2026-53634","aliases":["GHSA-vmwx-m75v-qvch"],"url":"https://o3.security/vulnerability/CVE-2026-53634","summary":"Sharp: Missing Authorization Check in Quick Creation Command Endpoints","details":"### Impact\nThe create and store endpoints of the Quick Creation Command feature did not enforce any authorization check. An authenticated Sharp user without create permission on a given entity could bypass the authorization layer and either retrieve the creation form or submit new records for that entity, as long as it had a Quick Creation Command handler configured.\n\n### Patches\nYes. The fix is included in version 9.22.3. Users should upgrade to that version or later.\n\n### Workarounds\nRemove or disable Quick Creation Command handlers (quickCreationCommandHandler()) on any entity list where unauthorized access is a concern, until an upgrade is possible.\n\n### Resources\n[PR #729](https://github.com/code16/sharp/pull/729)","published":"2026-06-10T20:03:33.950Z","modified":"2026-08-12T03:51:23.982046984Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"},"epss":{"score":0.00213,"percentile":0.11823,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"code16/sharp","fixedVersion":"9.22.3"}],"fix":{"url":"https://github.com/code16/sharp/commit/aa18a85fd8fef830988a336cad2278986729d21a","label":"code16/sharp@aa18a85"},"references":[{"type":"WEB","url":"https://github.com/code16/sharp/releases/tag/v9.22.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53634.json"},{"type":"ADVISORY","url":"https://github.com/code16/sharp/security/advisories/GHSA-vmwx-m75v-qvch"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53634"},{"type":"FIX","url":"https://github.com/code16/sharp/commit/aa18a85fd8fef830988a336cad2278986729d21a"},{"type":"FIX","url":"https://github.com/code16/sharp/pull/729"},{"type":"PACKAGE","url":"https://github.com/code16/sharp"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:23.982046984Z"}}