Wn backend module: Winter: Authenticated backend users can bypass Users controller permission checks (CVE-2026-35445)
Winter CMS versions prior to 1.2.13 contain a vulnerability where authenticated backend users can bypass permission checks on the Users controller by exploiting improper validation of the _handler POST field. This allows calling protected controller methods without proper authorization, potentially enabling unauthorized user management actions. The issue requires the attacker to have any authenticated backend access and valid session, as CSRF protections remain in place. The vulnerability has been fixed in version 1.2.13 with improved handler validation and controller restructuring.
AI Analysis
Technical Summary
Winter CMS backend module versions before 1.2.13 did not validate the _handler POST field in the same way as AJAX requests, allowing authenticated backend users to invoke any controller method, including protected and private ones, by submitting crafted POST requests. The Users controller specifically allowed bypass of the backend.manage_users permission for the myaccount action, enabling unauthorized calls to sensitive user management methods such as update_onDelete and update_onManualPasswordReset. Exploitation requires an authenticated backend session. The fix in 1.2.13 enforces handler name validation on postback requests, moves My Account functionality to a dedicated controller without user management methods, and applies model-level protections against unauthorized user modifications.
Potential Impact
Authenticated backend users with any level of access can bypass permission checks on the Users controller to invoke sensitive user management functions without proper authorization. This could lead to unauthorized deletion, restoration, suspension, unsuspension, or password reset of user accounts. However, exploitation requires a valid authenticated session and cannot be performed by unauthenticated attackers due to CSRF token verification on POST requests.
Mitigation Recommendations
A security fix is available and has been backported to all major Winter CMS versions (1.0, 1.1, and 1.2). Users should update to version 1.2.13 or later immediately. If upgrading is not possible, manual mitigations include validating the _handler POST field against the on[A-Z][\w+]* pattern before dispatching handlers and removing the conditional permission bypass in the Users controller for the myaccount action.
Wn backend module: Winter: Authenticated backend users can bypass Users controller permission checks (CVE-2026-35445)
Description
Winter CMS versions prior to 1.2.13 contain a vulnerability where authenticated backend users can bypass permission checks on the Users controller by exploiting improper validation of the _handler POST field. This allows calling protected controller methods without proper authorization, potentially enabling unauthorized user management actions. The issue requires the attacker to have any authenticated backend access and valid session, as CSRF protections remain in place. The vulnerability has been fixed in version 1.2.13 with improved handler validation and controller restructuring.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Winter CMS backend module versions before 1.2.13 did not validate the _handler POST field in the same way as AJAX requests, allowing authenticated backend users to invoke any controller method, including protected and private ones, by submitting crafted POST requests. The Users controller specifically allowed bypass of the backend.manage_users permission for the myaccount action, enabling unauthorized calls to sensitive user management methods such as update_onDelete and update_onManualPasswordReset. Exploitation requires an authenticated backend session. The fix in 1.2.13 enforces handler name validation on postback requests, moves My Account functionality to a dedicated controller without user management methods, and applies model-level protections against unauthorized user modifications.
Potential Impact
Authenticated backend users with any level of access can bypass permission checks on the Users controller to invoke sensitive user management functions without proper authorization. This could lead to unauthorized deletion, restoration, suspension, unsuspension, or password reset of user accounts. However, exploitation requires a valid authenticated session and cannot be performed by unauthenticated attackers due to CSRF token verification on POST requests.
Mitigation Recommendations
A security fix is available and has been backported to all major Winter CMS versions (1.0, 1.1, and 1.2). Users should update to version 1.2.13 or later immediately. If upgrading is not possible, manual mitigations include validating the _handler POST field against the on[A-Z][\w+]* pattern before dispatching handlers and removing the conditional permission bypass in the Users controller for the myaccount action.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-j5jq-cr68-v2xx
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-35445"]
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a7c9b2ebf8831d539cdb6c9
Added to database: 08/12/2026, 16:11:26 UTC
Last enriched: 08/12/2026, 16:22:17 UTC
Last updated: 08/13/2026, 00:18:37 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.