OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-76089

HIGH · CVSS 7.7 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Formie plugin for Craft CMS is vulnerable due to a lack of permission checks in the SentNotificationsController, allowing any authenticated user to access and enumerate notification IDs, revealing sensitive recipient information and complete HTML email bodies containing submitted form data. This poses a significant risk of data exposure for organizations using affected versions prior to 2.2.23 and 3.1.31. Users of the Formie plugin should prioritize updating to the latest versions to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76089
Severity
HIGH
CVSS
7.7
EPSS
0.24%

Original NVD Description

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs and read recipient headers and complete HTML email bodies containing submitted form data, even without the sent-notification viewing permission. This issue is fixed in versions 2.2.23 and 3.1.31.