Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 23 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Puemos
Puemos craftplan |
|
| Vendors & Products |
Puemos
Puemos craftplan |
Fri, 21 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sensitive credentials by exploiting an unconditional authorization policy on the Settings resource. Attackers can send a GET request to the settings API endpoint with a valid record ID to retrieve decrypted SMTP passwords, email API keys, and email API secrets due to the read policy using an always-allow authorization check that bypasses all identity verification. | |
| Title | Craftplan < 0.5.1 Broken Access Control Information Disclosure via Settings API | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T17:17:45.458Z
Reserved: 2026-08-19T21:47:08.937Z
Link: CVE-2026-76876
Updated: 2026-08-25T17:17:33.665Z
Status : Deferred
Published: 2026-08-21T20:16:44.680
Modified: 2026-08-31T20:50:15.927
Link: CVE-2026-76876
No data.
OpenCVE Enrichment
Updated: 2026-08-23T16:40:51Z