Skip to main content
EPSS 0.5%top 63%

CVE-2026-32639: CWE-289: Authentication Bypass by Alternate Name in wintercms winter

0
Medium
Published: 08/26/2026 (08/26/2026, 17:50:32 UTC)
Source: GCVE Database
Vendor/Project: wintercms
Product: winter

Description

Winter CMS versions up to 1.2.12 contain an authentication bypass vulnerability in the CMS Theme Editor AJAX handlers. These handlers do not enforce per-template-type permission checks, allowing authenticated backend users with any single CMS permission to perform unauthorized actions on other template types. Additionally, the AssetList widget permits unauthorized file uploads due to missing theme validation. This issue is fixed in version 1.2.13.

CVSS v3.1

Score 6.8medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Affected software

Packagistghsa
winter/wn-cms-module
Affected versions
<1.2.13

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/13/2026, 14:49:36 UTC

Technical Analysis

Winter CMS, built on Laravel, has a vulnerability (CVE-2026-32639) in versions prior to 1.2.13 where the CMS Theme Editor AJAX handlers fail to enforce specific permissions per template type. The CMS controller uses OR-logic across five permissions for section access, but individual AJAX handlers like onSave(), onDelete(), and onDeleteTemplates() do not verify that the user holds the exact permission for the template type requested. Consequently, a user with only cms.manage_pages permission can delete layouts, modify partials, or read content files outside their authorized scope. Furthermore, the AssetList widget is accessible to any user passing the controller gate regardless of cms.manage_assets permission, and its onUpload() handler lacks theme validation, enabling unauthorized file uploads to the active theme's asset directory. Exploitation requires an authenticated backend user with at least one CMS Theme Editor permission. The vulnerability is resolved in version 1.2.13.

Potential Impact

An authenticated backend user with any single CMS Theme Editor permission can bypass intended permission restrictions to modify or delete templates outside their authorized scope, and upload unauthorized files to the active theme's asset directory. This can lead to unauthorized content modification and potential asset injection. The CVSS score is 6.8 (medium severity) with high confidentiality impact but no integrity or availability impact.

Mitigation Recommendations

Upgrade Winter CMS to version 1.2.13 or later, where this issue is fixed. Users should ensure that backend accounts have only necessary CMS permissions. No additional mitigations are specified by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-5c4f-9pq9-6c77
Osv Schema Version
1.4.0
Aliases
["CVE-2026-32639"]
Ecosystems
["Packagist"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6a7c9b2ebf8831d539cdb6d1

Added to database: 08/12/2026, 16:11:26 UTC

Last enriched: 09/13/2026, 14:49:36 UTC

Last updated: 09/27/2026, 13:47:44 UTC

Views: 42

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses