VYPR
Medium severity5.3NVD Advisory· Published Sep 30, 2026· Updated Sep 30, 2026

CVE-2026-103476

CVE-2026-103476

Description

yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished articles without authentication or authorization checks.

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.