OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-76086

HIGH · CVSS 8.5 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Formie plugin for Craft CMS contains a vulnerability that allows authenticated attackers with low privileges to access form integration settings without proper permissions, enabling them to manipulate outbound API requests. This could lead to exposure of sensitive integration credentials and internal network responses, posing a significant risk to sites that allow front-end user authentication. Organizations using affected versions should prioritize upgrading to versions 2.2.23 or 3.1.31 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76086
Severity
HIGH
CVSS
8.5
EPSS
0.29%

Original NVD Description

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings control panel action in IntegrationsController::actionFormSettings is reachable without the required form integration permissions and passes request-supplied settings to a configured integration. An authenticated attacker can replace outbound host properties such as apiUrl while the server uses stored API keys or OAuth tokens, causing non-blind server-side requests to an attacker-controlled or internal host and returning the remote response. This residual flaw remained because the permission gate added in version 3.1.28 excluded the form-settings action. Sites that permit low-privileged or front-end user authentication can therefore expose integration credentials and internal network responses. This issue is fixed in versions 2.2.23 and 3.1.31.