SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-56092

HIGH · CVSS 7.6 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability allows anonymous users to bypass access restrictions on cached pages by exploiting improperly enforced frontend-group and subpage-inheritance settings during indexer sub-requests. This flaw can lead to unauthorized access to sensitive content, posing a significant risk to the integrity of web applications. Organizations using affected products should prioritize remediation to protect against potential data exposure and unauthorized access.

CVE
CVE-2026-56092
Severity
HIGH
CVSS
7.6
EPSS
0.22%

Original NVD Description

The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions on cached pages.