CVE-2026-28696Disclosure(craftcms / craft_cms)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch craftcms craft_cms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal reference tags (e.g., {user:1:email}), can be abused by both authenticated users and unauthenticated guests (if a Public Schema is enabled) to access sensitive attributes of any element in the CMS. The implementation in Elements::parseRefs fails to perform authorization checks, allowing attackers to read data they are not authorized to view. This vulnerability is fixed in 4.17.0-beta.1 and 5.9.0-beta.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • craft_cms

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
craft_cms

2 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-04: 2Patch / Workaround · 2026-03-04: 1Technical Details · 2026-03-04: 103-04
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-28696 Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal reference tags (e.g.… https://www.cve.org/CVERecord?id=CVE-2026-28696

    Post summary

    A vulnerability in Craft CMS’s GraphQL @parseRefs directive is disclosed, with patched versions noted, but no exploit or active exploitation is reported.

    00000145
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28696 Craft affected by IDOR via GraphQL @parseRefs Intel Report: https://ift.tt/F1GrRqo

    Post summary

    The alert announces that Craft is affected by CVE‑2026‑28696, an IDOR vulnerability via GraphQL, but provides no evidence of active exploitation, patches, or a proof‑of‑concept.

    0000038
    344 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appcraftcmscraft_cms---
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms5.0.0--
Appcraftcmscraft_cms5.0.0--

Explore more