Unrated severityNVD Advisory· Published Mar 24, 2026· Updated Mar 25, 2026
Unauthenticated arbitrary PHP class instantiation
CVE-2026-23923
Description
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.