Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Wn backend module: Winter: Authenticated backend users can bypass Users controller permission checks (CVE-2026-35445)

0
High
Published: 08/12/2026 (08/12/2026, 15:15:17 UTC)
Source: GCVE Database
Product: winter/wn-backend-module

Description

Winter CMS versions prior to 1.2.13 contain a vulnerability where authenticated backend users can bypass permission checks on the Users controller by exploiting improper validation of the _handler POST field. This allows calling protected controller methods without proper authorization, potentially enabling unauthorized user management actions. The issue requires the attacker to have any authenticated backend access and valid session, as CSRF protections remain in place. The vulnerability has been fixed in version 1.2.13 with improved handler validation and controller restructuring.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
Low
Vuln. Availability
None
Subsq. Confidentiality
High
Subsq. Integrity
Low
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N

Affected software

Packagistghsa
winter/wn-backend-module
Affected versions
<1.2.13

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 16:22:17 UTC

Technical Analysis

Winter CMS backend module versions before 1.2.13 did not validate the _handler POST field in the same way as AJAX requests, allowing authenticated backend users to invoke any controller method, including protected and private ones, by submitting crafted POST requests. The Users controller specifically allowed bypass of the backend.manage_users permission for the myaccount action, enabling unauthorized calls to sensitive user management methods such as update_onDelete and update_onManualPasswordReset. Exploitation requires an authenticated backend session. The fix in 1.2.13 enforces handler name validation on postback requests, moves My Account functionality to a dedicated controller without user management methods, and applies model-level protections against unauthorized user modifications.

Potential Impact

Authenticated backend users with any level of access can bypass permission checks on the Users controller to invoke sensitive user management functions without proper authorization. This could lead to unauthorized deletion, restoration, suspension, unsuspension, or password reset of user accounts. However, exploitation requires a valid authenticated session and cannot be performed by unauthenticated attackers due to CSRF token verification on POST requests.

Mitigation Recommendations

A security fix is available and has been backported to all major Winter CMS versions (1.0, 1.1, and 1.2). Users should update to version 1.2.13 or later immediately. If upgrading is not possible, manual mitigations include validating the _handler POST field against the on[A-Z][\w+]* pattern before dispatching handlers and removing the conditional permission bypass in the Users controller for the myaccount action.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-j5jq-cr68-v2xx
Osv Schema Version
1.4.0
Aliases
["CVE-2026-35445"]
Ecosystems
["Packagist"]
Database Specific Severity
HIGH
Cvss Version
4.0

Threat ID: 6a7c9b2ebf8831d539cdb6c9

Added to database: 08/12/2026, 16:11:26 UTC

Last enriched: 08/12/2026, 16:22:17 UTC

Last updated: 08/13/2026, 00:18:37 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses