CVE-2026-76089

high

Description

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs and read recipient headers and complete HTML email bodies containing submitted form data, even without the sent-notification viewing permission. This issue is fixed in versions 2.2.23 and 3.1.31.

References

https://github.com/verbb/formie/security/advisories/GHSA-9rg8-2wvr-fgjh

https://github.com/verbb/formie/releases/tag/3.1.31

https://github.com/verbb/formie/releases/tag/2.2.23

https://github.com/verbb/formie/commit/ff81a895fa91a2e4efb8d4714501ba2d92df0b76

https://github.com/verbb/formie/commit/9f4e23c36b907ed7677563231eaba373fdb8b84b

Details

Source: Mitre, NVD

Published: 2026-09-23

Updated: 2026-09-23

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 7.7

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Severity: High

EPSS

EPSS: 0.00238