CVE-2026-77140EPSS p32.5%

CVE-2026-77140CVE-2026-77140

Description

The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. An unauthenticated visitor who knows the UID of a visible employee record can send a direct POST request to the update action and overwrite that record without a valid edit link or any ownership check.

Scoring

EPSS0.41% probability of exploitation · percentile 32.5% · 2026-10-05T12:00:23Z
Last modified2026-09-28
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.