Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. winter/wn-backend-module
  4. ›
  5. CVE-2026-35445

CVE-2026-35445: Winter: Authenticated backend users can bypass Users controller permission checks

August 12, 2026

Affected versions of Winter CMS did not validate the handler name submitted through the form postback mechanism (_handler POST field) in the same way as AJAX requests (X_WINTER_REQUEST_HANDLER header). The AJAX path validates that handler names match the on[A-Z][\w+]* pattern, but the postback path passed the handler name directly to the handler dispatcher with no validation.

This allowed an authenticated backend user to call any method on a controller — including action-prefixed, protected, and private methods — by submitting a crafted POST request with a _handler field, as long as the controller either:

  • Contains a publicly available action via the $publicActions property, or
  • Degrades or removes the $requiredPermissions check in its constructor based on a condition

The backend’s own Users controller was affected by the second scenario: it set $requiredPermissions to null for the myaccount action, allowing any authenticated backend user to access the controller without the backend.manage_users permission. Combined with the postback bypass, this allowed calling controller methods such as update_onDelete, update_onRestore, update_onUnsuspendUser, and update_onManualPasswordReset with attacker-controlled parameters.

Note that CSRF tokens are still verified on all POST requests, so the attacker must be logged into the backend with a valid session.

To actively exploit this security issue, an attacker would need access to the Backend with a user account with any level of access.

The Winter CMS maintainers strongly recommend that all Winter CMS sites that have any reliance on the roles & permissions system to update immediately. Security fixes have been backported to all major versions of Winter (1.0, 1.1, and 1.2).

References

  • github.com/advisories/GHSA-j5jq-cr68-v2xx
  • github.com/wintercms/winter/releases/tag/v1.2.13
  • github.com/wintercms/winter/security/advisories/GHSA-j5jq-cr68-v2xx
  • nvd.nist.gov/vuln/detail/CVE-2026-35445

Code Behaviors & Features

Detect and mitigate CVE-2026-35445 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.2.13

Fixed versions

  • 1.2.13

Solution

Upgrade to version 1.2.13 or above.

Impact 8.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-285: Improper Authorization
  • CWE-639: Authorization Bypass Through User-Controlled Key

Source file

packagist/winter/wn-backend-module/CVE-2026-35445.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 13 Aug 2026 12:24:08 +0000.