kaminuma@kaminuma_devDisclosure
The post announces that CVE-2026-41128 has been publicly disclosed for Craft CMS and expresses gratitude for the fix, without mentioning exploitation or technical specifics.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE-2026-41128 for Craft CMS, detailing how the actionSavePermissions endpoint can be abused in certain versions, but provides no PoC, exploit, patches, or active exploitation information.
CVE@CVEnewDisclosure
The excerpt offers a high‑level vulnerability disclosure for Craft CMS, noting the affected endpoint and permissions without detailing a PoC, exploit, or mitigation.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The excerpt announces CVE‑2026‑41128, detailing an unauthorized user group removal flaw in Craft CMS versions 5.6.0 to 5.9.14, and links to a vulnerability information page.