PT-2026-79439 · Craftplan · Craftplan

·

CVE-2026-76876

·

Published

2026-08-21

·

Updated

2026-08-25

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Craftplan versions prior to 0.5.1
Description Broken access control allows unauthenticated attackers to read sensitive credentials by exploiting an unconditional authorization policy on the Settings resource. By sending a GET request to the settings API endpoint with a valid record ID, attackers can retrieve decrypted SMTP passwords, email API keys, and email API secrets. This occurs because the read policy uses an always-allow authorization check that bypasses all identity verification.
Recommendations Update Craftplan to version 0.5.1 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76876

Affected Products

Craftplan