Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sensitive credentials by exploiting an unconditional authorization policy on the Settings resource. Attackers can send a GET request to the settings API endpoint with a valid record ID to retrieve decrypted SMTP passwords, email API keys, and email API secrets due to the read policy using an always-allow authorization check that bypasses all identity verification. | |
| Title | Craftplan < 0.5.1 Broken Access Control Information Disclosure via Settings API | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-21T19:38:45.203Z
Reserved: 2026-08-19T21:47:08.937Z
Link: CVE-2026-76876
No data.
Status : Received
Published: 2026-08-21T20:16:44.680
Modified: 2026-08-21T20:16:44.680
Link: CVE-2026-76876
No data.
OpenCVE Enrichment
No data.
-
CWE-862
Missing Authorization