CVE-2026-11764
Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
09/06/2026
Last modified:
23/07/2026
Description
When creating an export of all reusable media, the secrets of connected <br />
gift cards were included in the export even if the user creating the <br />
export does not have permission to view gift cards. This is inconsistent<br />
with the UI and API where only the first letters of the gift card <br />
secret are shown. Therefore, it allows circumventing a permission <br />
boundary.



