๐Ÿ” CVE Alert

CVE-2026-32639

MEDIUM 6.8

Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads

CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type permission checks, allowing a backend user with any single CMS permission to act on template types outside their authorized scope. The CMS controller gated access to the section as a whole using OR-logic across its five permissions, but individual handlers such as onSave(), onDelete(), and onDeleteTemplates() did not verify that the user held the specific permission for the requested template type, so a user with only cms.manage_pages could craft AJAX requests to delete layouts, modify partials, or read content files. Separately, the AssetList widget was registered for any user who passed the controller gate regardless of the cms.manage_assets permission, and its onUpload() handler omitted the theme-validation call present on the other mutating handlers, permitting unauthorized file uploads into the active theme's asset directory. Exploitation requires an authenticated backend account holding at least one of the CMS Theme Editor permissions. This issue is fixed in version 1.2.13.

CWE CWE-289
Vendor wintercms
Product winter
Published Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for wintercms winter

Be the first to know when new medium vulnerabilities affecting wintercms winter are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

wintercms / winter
< 1.2.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/wintercms/winter/security/advisories/GHSA-5c4f-9pq9-6c77 github.com: https://github.com/wintercms/winter/commit/164c62524e8abc153d09c6c35916278bdb746a2b github.com: https://github.com/wintercms/winter/commit/5391afa242eba3c476869035b7492e50a262c46b github.com: https://github.com/wintercms/winter/releases/tag/v1.2.13