๐Ÿ” CVE Alert

CVE-2026-76089

HIGH 7.7

Formie: Missing authorization on sent notification resend modal exposes submission PII

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs and read recipient headers and complete HTML email bodies containing submitted form data, even without the sent-notification viewing permission. This issue is fixed in versions 2.2.23 and 3.1.31.

CWE CWE-200 CWE-639 CWE-862
Vendor verbb
Product formie
Published Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for verbb formie

Be the first to know when new high vulnerabilities affecting verbb formie are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

verbb / formie
< 2.2.23 >= 3.0.0, < 3.1.31

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/verbb/formie/security/advisories/GHSA-9rg8-2wvr-fgjh github.com: https://github.com/verbb/formie/commit/9f4e23c36b907ed7677563231eaba373fdb8b84b github.com: https://github.com/verbb/formie/commit/ff81a895fa91a2e4efb8d4714501ba2d92df0b76 github.com: https://github.com/verbb/formie/releases/tag/2.2.23 github.com: https://github.com/verbb/formie/releases/tag/3.1.31