CVE-2026-76087: 
PHP 취약성 분석 및 완화

개요

CVE-2026-76087 is an authorization bypass vulnerability in Formie, a Craft CMS plugin for building forms developed by verbb. The formie/submissions/submit action in SubmissionsController::actionSubmit blindly trusts a client-supplied submissionId when loading an incomplete submission, with no session binding, ownership check, or edit token validation. This allows unauthenticated attackers to enumerate sequential submission IDs and overwrite or hijack other users' in-progress multi-page or save-for-later submissions. Affected versions are Formie < 2.2.23 (Craft 4) and >= 3.0.0, < 3.1.31 (Craft 5). The vulnerability was disclosed on September 23, 2026, and carries a CVSS v3.1 base score of 8.2 (High) (GitHub Advisory).

기술적 세부 사항

The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key) and CWE-862 (Missing Authorization). The actionSubmit method in SubmissionsController.php accepted a client-supplied submissionId POST parameter and loaded the corresponding incomplete submission without verifying that it belonged to the requesting user's session or validating a submissionEditToken. Because submission IDs are sequential integers, an unauthenticated attacker can trivially enumerate them. This vulnerability is an incomplete remediation of CVE-2026-47266 (GHSA-pgxq-p76c-x9cg), which added edit-token validation to the save-submission action but left the submit action unprotected. The fix introduces a new _authorizeExistingSubmission() method that requires the submission ID to match the session-bound submission (Form::getCurrentSubmission()) or a valid submissionEditToken when editingSubmission is set, and also rejects cross-form submission ID reuse (GitHub Advisory, Patch Commit 323c2fe, Patch Commit 78a298a).

영향

An unauthenticated attacker can overwrite or hijack any other user's incomplete (multi-page or save-for-later) form submission by substituting a guessed sequential submission ID. Tampered submission data is persisted to the database and can be forwarded through email notifications and third-party integrations when the submission is eventually completed, potentially leading to data integrity violations, misinformation propagation, or abuse of downstream integrations. Confidentiality impact is rated low (limited read access to submission data), while integrity impact is rated high due to the ability to arbitrarily modify another user's submission content. Completed submissions are not affected due to the isIncomplete=true filter (GitHub Advisory).

악용 가능성

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. The vulnerability requires no authentication, no user interaction, and low attack complexity, making it straightforward to exploit manually with basic HTTP tooling. The EPSS score is reported as 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The vulnerability was reported by Jorge González (jorge@jmilla.es) and disclosed via GitHub Security Advisories on September 23, 2026 (GitHub Advisory).

착취 단계

  1. Reconnaissance: Identify Craft CMS sites using the Formie plugin (e.g., via HTTP response headers, HTML source referencing Formie assets, or Wappalyzer fingerprinting). Confirm the site exposes the front-end form submission endpoint (/actions/formie/submissions/submit).
  2. Initiate a legitimate submission: Submit a multi-page or save-for-later form on the target site to observe the structure of the submissionId parameter returned in the response or embedded in the form HTML.
  3. Enumerate submission IDs: Since submission IDs are sequential integers, iterate over adjacent integer values (e.g., submissionId=100, 101, 102, ...) to identify other users' in-progress incomplete submissions.
  4. Craft a malicious POST request: Send a POST request to formie/submissions/submit with the target submissionId and attacker-controlled field values, without providing a valid session or edit token. The server will accept the request due to the missing authorization check.
  5. Overwrite submission data: The tampered field values are persisted to the database, replacing the legitimate user's in-progress submission data.
  6. Trigger downstream effects: If the victim (or the attacker) subsequently completes the submission, the manipulated data is forwarded through configured email notifications and third-party integrations (GitHub Advisory).

타협의 징후

  • Network: Repeated POST requests to /actions/formie/submissions/submit from a single IP address with sequentially incrementing submissionId values in the request body; requests lacking a valid session cookie or submissionEditToken.
  • Logs: Web server or Craft CMS application logs showing multiple submission attempts with different submissionId values from the same source IP in a short time window; HTTP 200 responses to submission requests that do not correspond to the requesting user's session.
  • Application: Unexpected changes to in-progress form submission data in the Craft CMS control panel (submissions showing modified field values not entered by the original submitter); notifications or integration payloads containing data inconsistent with the original submitter's input.

완화 및 해결 방법

Upgrade Formie to version 2.2.23 (for Craft 4) or 3.1.31 (for Craft 5), which enforce session-bound or edit-token authorization when resuming incomplete submissions via the submit action. No reliable workaround exists without upgrading; disabling multi-page forms or the save-for-later feature reduces exposure but does not fully eliminate the vulnerability. Administrators should review recent incomplete submissions in the Craft CMS control panel for unexpected data modifications (GitHub Advisory, Release 2.2.23, Release 3.1.31).

추가 자료


근원: 이 보고서는 AI를 사용하여 생성되었습니다.

관련 PHP 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-91768MEDIUM6.5
  • PHP logoPHP
  • php:7.4::php-common
아니요예Sep 25, 2026
CVE-2026-91767MEDIUM6.5
  • PHP logoPHP
  • php-opcache
아니요예Sep 25, 2026
CVE-2026-92842MEDIUM5.9
  • PHP logoPHP
  • php:8.2::php-process
아니요예Sep 25, 2026
CVE-2026-91766MEDIUM5.9
  • PHP logoPHP
  • php8.4-fpm
아니요예Sep 25, 2026
CVE-2026-91769MEDIUM4.3
  • PHP logoPHP
  • php-fpm
아니요예Sep 25, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자