cvedb.io
CVE-2026-46721
UNKNOWN · CVSS n/a
EPSS exploitation probability: 0%
Published 2026-05-19T10:16:24.853 · Last modified 2026-06-17T10:53:51.843

Summary

The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.