PT-2026-48549 · Laravel · Sharp
CVE-2026-53634
·
Published
2026-06-10
·
Updated
2026-07-08
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sharp versions 9.0.0 through 9.22.2
Description
Sharp is a content management framework built for Laravel as a package. The 'create' and 'store' endpoints of the Quick Creation Command feature fail to enforce authorization checks. This allows an authenticated user lacking create permissions for a specific entity to bypass the authorization layer to retrieve the creation form or submit new records, provided a Quick Creation Command handler is configured.
Recommendations
Update to version 9.22.3.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sharp