SEPTEMBER 27, 2026
Live Feed
Back to database
Case File

CVE-2026-11764

UNKNOWN · CVSS N/A EPSS 0.23%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-06-09 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. See the original NVD description below for full technical details.

CVE
CVE-2026-11764
Severity
UNKNOWN
CVSS
N/A
EPSS
0.23%

Original NVD Description

When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if the user creating the export does not have permission to view gift cards. This is inconsistent with the UI and API where only the first letters of the gift card secret are shown. Therefore, it allows circumventing a permission boundary.