
CVE-2026-21626 Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure https://www.cve.org/CVERecord?id=CVE-2026-21626
Post summary
A newly disclosed CVE (2026-21626) involves improper access control for forum post custom fields in JSON output, leading to potential information disclosure.

