CVE-2026-76087:
PHP 취약성 분석 및 완화
개요
CVE-2026-76087 is an authorization bypass vulnerability in Formie, a Craft CMS plugin for building forms developed by verbb. The formie/submissions/submit action in SubmissionsController::actionSubmit blindly trusts a client-supplied submissionId when loading an incomplete submission, with no session binding, ownership check, or edit token validation. This allows unauthenticated attackers to enumerate sequential submission IDs and overwrite or hijack other users' in-progress multi-page or save-for-later submissions. Affected versions are Formie < 2.2.23 (Craft 4) and >= 3.0.0, < 3.1.31 (Craft 5). The vulnerability was disclosed on September 23, 2026, and carries a CVSS v3.1 base score of 8.2 (High) (GitHub Advisory).
기술적 세부 사항
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key) and CWE-862 (Missing Authorization). The actionSubmit method in SubmissionsController.php accepted a client-supplied submissionId POST parameter and loaded the corresponding incomplete submission without verifying that it belonged to the requesting user's session or validating a submissionEditToken. Because submission IDs are sequential integers, an unauthenticated attacker can trivially enumerate them. This vulnerability is an incomplete remediation of CVE-2026-47266 (GHSA-pgxq-p76c-x9cg), which added edit-token validation to the save-submission action but left the submit action unprotected. The fix introduces a new _authorizeExistingSubmission() method that requires the submission ID to match the session-bound submission (Form::getCurrentSubmission()) or a valid submissionEditToken when editingSubmission is set, and also rejects cross-form submission ID reuse (GitHub Advisory, Patch Commit 323c2fe, Patch Commit 78a298a).
영향
An unauthenticated attacker can overwrite or hijack any other user's incomplete (multi-page or save-for-later) form submission by substituting a guessed sequential submission ID. Tampered submission data is persisted to the database and can be forwarded through email notifications and third-party integrations when the submission is eventually completed, potentially leading to data integrity violations, misinformation propagation, or abuse of downstream integrations. Confidentiality impact is rated low (limited read access to submission data), while integrity impact is rated high due to the ability to arbitrarily modify another user's submission content. Completed submissions are not affected due to the isIncomplete=true filter (GitHub Advisory).
악용 가능성
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. The vulnerability requires no authentication, no user interaction, and low attack complexity, making it straightforward to exploit manually with basic HTTP tooling. The EPSS score is reported as 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The vulnerability was reported by Jorge González (jorge@jmilla.es) and disclosed via GitHub Security Advisories on September 23, 2026 (GitHub Advisory).
착취 단계
- Reconnaissance: Identify Craft CMS sites using the Formie plugin (e.g., via HTTP response headers, HTML source referencing Formie assets, or Wappalyzer fingerprinting). Confirm the site exposes the front-end form submission endpoint (
/actions/formie/submissions/submit). - Initiate a legitimate submission: Submit a multi-page or save-for-later form on the target site to observe the structure of the
submissionIdparameter returned in the response or embedded in the form HTML. - Enumerate submission IDs: Since submission IDs are sequential integers, iterate over adjacent integer values (e.g.,
submissionId=100,101,102, ...) to identify other users' in-progress incomplete submissions. - Craft a malicious POST request: Send a POST request to
formie/submissions/submitwith the targetsubmissionIdand attacker-controlled field values, without providing a valid session or edit token. The server will accept the request due to the missing authorization check. - Overwrite submission data: The tampered field values are persisted to the database, replacing the legitimate user's in-progress submission data.
- Trigger downstream effects: If the victim (or the attacker) subsequently completes the submission, the manipulated data is forwarded through configured email notifications and third-party integrations (GitHub Advisory).
타협의 징후
- Network: Repeated POST requests to
/actions/formie/submissions/submitfrom a single IP address with sequentially incrementingsubmissionIdvalues in the request body; requests lacking a valid session cookie orsubmissionEditToken. - Logs: Web server or Craft CMS application logs showing multiple submission attempts with different
submissionIdvalues from the same source IP in a short time window; HTTP 200 responses to submission requests that do not correspond to the requesting user's session. - Application: Unexpected changes to in-progress form submission data in the Craft CMS control panel (submissions showing modified field values not entered by the original submitter); notifications or integration payloads containing data inconsistent with the original submitter's input.
완화 및 해결 방법
Upgrade Formie to version 2.2.23 (for Craft 4) or 3.1.31 (for Craft 5), which enforce session-bound or edit-token authorization when resuming incomplete submissions via the submit action. No reliable workaround exists without upgrading; disabling multi-page forms or the save-for-later feature reduces exposure but does not fully eliminate the vulnerability. Administrators should review recent incomplete submissions in the Craft CMS control panel for unexpected data modifications (GitHub Advisory, Release 2.2.23, Release 3.1.31).
추가 자료
근원: 이 보고서는 AI를 사용하여 생성되었습니다.
관련 PHP 취약점:
무료 취약성 평가
클라우드 보안 태세를 벤치마킹합니다
9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.
추가 Wiz 리소스
맞춤형 데모 받기
맞춤형 데모 신청하기
"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."