
CVE-2026-28782 Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, the "Duplicate" entry action does not properly verify if the user has permission … https://www.cve.org/CVERecord?id=CVE-2026-28782
Post summary
The text announces CVE-2026-28782 as a permission bypass issue in Craft CMS, noting the affected versions and providing a link to the official CVE record.
