CVE-2026-76876: Missing Authorization in puemos craftplan
Description
Craftplan versions before 0.5.1 have a broken access control vulnerability that allows unauthenticated attackers to read sensitive credentials. The flaw is due to an unconditional authorization policy on the Settings resource, permitting GET requests with valid record IDs to retrieve decrypted SMTP passwords, email API keys, and secrets without identity verification.
CVSS v4.0
Score 8.2high
Affected software
puemos
craftplan
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-76876 describes a broken access control vulnerability in puemos craftplan prior to version 0.5.1. The vulnerability arises because the Settings resource uses an always-allow authorization policy that bypasses identity verification. This allows unauthenticated attackers to send GET requests to the settings API endpoint with a valid record ID and retrieve sensitive credentials such as decrypted SMTP passwords, email API keys, and email API secrets. The CVSS 4.0 score is 8.2, indicating high severity, with network attack vector, high attack complexity, and no privileges or user interaction required.
Potential Impact
An attacker can obtain sensitive credentials including SMTP passwords and email API keys without authentication, potentially leading to unauthorized access to email services or further compromise of the affected environment. The vulnerability impacts confidentiality of sensitive information stored in the Settings resource.
Mitigation Recommendations
A fix is available in craftplan version 0.5.1. Users should upgrade to version 0.5.1 or later to remediate this vulnerability. Until upgraded, restrict access to the settings API endpoint to trusted users only.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-19T21:47:08.937Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a88ac8bacd9273b49a43044
Added to database: 08/21/2026, 19:52:43 UTC
Last enriched: 09/10/2026, 17:21:21 UTC
Last updated: 10/05/2026, 18:48:22 UTC
Views: 60
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.