Wn backend module: Winter: Authenticated backend users can bypass Users controller permission checks (CVE-2026-35445)
Winter CMS versions prior to 1.2.13 contain a vulnerability in the backend module where authenticated backend users can bypass permission checks on the Users controller. This occurs because the backend did not properly validate the _handler POST field, allowing invocation of arbitrary controller methods, including those normally protected. The Users controller was specifically affected due to a null $requiredPermissions setting on the myaccount action, enabling unauthorized user-management operations. The issue is fixed in version 1.2.13.
AI Analysis
Technical Summary
Winter CMS backend module versions before 1.2.13 fail to validate the _handler POST field in form postbacks, enabling authenticated backend users to invoke arbitrary controller methods, including protected and private ones. AJAX requests enforce a handler name pattern, but the postback path does not, allowing bypass of roles and permissions. The Users controller's myaccount action sets $requiredPermissions to null, permitting any authenticated backend user to execute sensitive user-management methods like update_onDelete and update_onManualPasswordReset without the backend.manage_users permission. This vulnerability is resolved in version 1.2.13.
Potential Impact
Authenticated backend users can bypass permission checks and invoke sensitive user-management functions without proper authorization. This could lead to unauthorized user deletions or password resets, compromising user accounts and administrative control within the CMS.
Mitigation Recommendations
Upgrade Winter CMS backend module to version 1.2.13 or later, where this vulnerability is fixed. Applying this official patch eliminates the permission bypass issue. No additional mitigation is required once the update is applied.
Wn backend module: Winter: Authenticated backend users can bypass Users controller permission checks (CVE-2026-35445)
Description
Winter CMS versions prior to 1.2.13 contain a vulnerability in the backend module where authenticated backend users can bypass permission checks on the Users controller. This occurs because the backend did not properly validate the _handler POST field, allowing invocation of arbitrary controller methods, including those normally protected. The Users controller was specifically affected due to a null $requiredPermissions setting on the myaccount action, enabling unauthorized user-management operations. The issue is fixed in version 1.2.13.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Winter CMS backend module versions before 1.2.13 fail to validate the _handler POST field in form postbacks, enabling authenticated backend users to invoke arbitrary controller methods, including protected and private ones. AJAX requests enforce a handler name pattern, but the postback path does not, allowing bypass of roles and permissions. The Users controller's myaccount action sets $requiredPermissions to null, permitting any authenticated backend user to execute sensitive user-management methods like update_onDelete and update_onManualPasswordReset without the backend.manage_users permission. This vulnerability is resolved in version 1.2.13.
Potential Impact
Authenticated backend users can bypass permission checks and invoke sensitive user-management functions without proper authorization. This could lead to unauthorized user deletions or password resets, compromising user accounts and administrative control within the CMS.
Mitigation Recommendations
Upgrade Winter CMS backend module to version 1.2.13 or later, where this vulnerability is fixed. Applying this official patch eliminates the permission bypass issue. No additional mitigation is required once the update is applied.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-j5jq-cr68-v2xx
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-35445"]
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a7c9b2ebf8831d539cdb6c9
Added to database: 08/12/2026, 16:11:26 UTC
Last enriched: 09/12/2026, 05:33:13 UTC
Last updated: 09/25/2026, 01:47:42 UTC
Views: 38
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.