PT-2026-48549 · Laravel · Sharp

CVE-2026-53634

·

Published

2026-06-10

·

Updated

2026-07-08

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sharp versions 9.0.0 through 9.22.2
Description Sharp is a content management framework built for Laravel as a package. The 'create' and 'store' endpoints of the Quick Creation Command feature fail to enforce authorization checks. This allows an authenticated user lacking create permissions for a specific entity to bypass the authorization layer to retrieve the creation form or submit new records, provided a Quick Creation Command handler is configured.
Recommendations Update to version 9.22.3.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53634
GHSA-VMWX-M75V-QVCH

Affected Products

Sharp