CVE-2026-56092EPSS p19.4%
CVE-2026-56092CVE-2026-56092
Description
The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions on cached pages.
Scoring
| EPSS | 0.29% probability of exploitation · percentile 19.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-17 |