CVE-2026-32639: CWE-289: Authentication Bypass by Alternate Name in wintercms winter
Winter CMS versions up to 1.2.12 contain an authentication bypass vulnerability in the CMS Theme Editor AJAX handlers. These handlers do not enforce per-template-type permission checks, allowing authenticated backend users with any single CMS permission to perform unauthorized actions on other template types. Additionally, the AssetList widget permits unauthorized file uploads due to missing theme validation. This issue is fixed in version 1.2.13.
AI Analysis
Technical Summary
Winter CMS, built on Laravel, has a vulnerability (CVE-2026-32639) in versions prior to 1.2.13 where the CMS Theme Editor AJAX handlers fail to enforce specific permissions per template type. The CMS controller uses OR-logic across five permissions for section access, but individual AJAX handlers like onSave(), onDelete(), and onDeleteTemplates() do not verify that the user holds the exact permission for the template type requested. Consequently, a user with only cms.manage_pages permission can delete layouts, modify partials, or read content files outside their authorized scope. Furthermore, the AssetList widget is accessible to any user passing the controller gate regardless of cms.manage_assets permission, and its onUpload() handler lacks theme validation, enabling unauthorized file uploads to the active theme's asset directory. Exploitation requires an authenticated backend user with at least one CMS Theme Editor permission. The vulnerability is resolved in version 1.2.13.
Potential Impact
An authenticated backend user with any single CMS Theme Editor permission can bypass intended permission restrictions to modify or delete templates outside their authorized scope, and upload unauthorized files to the active theme's asset directory. This can lead to unauthorized content modification and potential asset injection. The CVSS score is 6.8 (medium severity) with high confidentiality impact but no integrity or availability impact.
Mitigation Recommendations
Upgrade Winter CMS to version 1.2.13 or later, where this issue is fixed. Users should ensure that backend accounts have only necessary CMS permissions. No additional mitigations are specified by the vendor advisory.
CVE-2026-32639: CWE-289: Authentication Bypass by Alternate Name in wintercms winter
Description
Winter CMS versions up to 1.2.12 contain an authentication bypass vulnerability in the CMS Theme Editor AJAX handlers. These handlers do not enforce per-template-type permission checks, allowing authenticated backend users with any single CMS permission to perform unauthorized actions on other template types. Additionally, the AssetList widget permits unauthorized file uploads due to missing theme validation. This issue is fixed in version 1.2.13.
CVSS v3.1
Score 6.8medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Winter CMS, built on Laravel, has a vulnerability (CVE-2026-32639) in versions prior to 1.2.13 where the CMS Theme Editor AJAX handlers fail to enforce specific permissions per template type. The CMS controller uses OR-logic across five permissions for section access, but individual AJAX handlers like onSave(), onDelete(), and onDeleteTemplates() do not verify that the user holds the exact permission for the template type requested. Consequently, a user with only cms.manage_pages permission can delete layouts, modify partials, or read content files outside their authorized scope. Furthermore, the AssetList widget is accessible to any user passing the controller gate regardless of cms.manage_assets permission, and its onUpload() handler lacks theme validation, enabling unauthorized file uploads to the active theme's asset directory. Exploitation requires an authenticated backend user with at least one CMS Theme Editor permission. The vulnerability is resolved in version 1.2.13.
Potential Impact
An authenticated backend user with any single CMS Theme Editor permission can bypass intended permission restrictions to modify or delete templates outside their authorized scope, and upload unauthorized files to the active theme's asset directory. This can lead to unauthorized content modification and potential asset injection. The CVSS score is 6.8 (medium severity) with high confidentiality impact but no integrity or availability impact.
Mitigation Recommendations
Upgrade Winter CMS to version 1.2.13 or later, where this issue is fixed. Users should ensure that backend accounts have only necessary CMS permissions. No additional mitigations are specified by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-5c4f-9pq9-6c77
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-32639"]
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a7c9b2ebf8831d539cdb6d1
Added to database: 08/12/2026, 16:11:26 UTC
Last enriched: 09/13/2026, 14:49:36 UTC
Last updated: 09/27/2026, 13:47:44 UTC
Views: 42
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.