CVE-2026-11764

Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
09/06/2026
Last modified:
23/07/2026

Description

When creating an export of all reusable media, the secrets of connected <br /> gift cards were included in the export even if the user creating the <br /> export does not have permission to view gift cards. This is inconsistent<br /> with the UI and API where only the first letters of the gift card <br /> secret are shown. Therefore, it allows circumventing a permission <br /> boundary.

References to Advisories, Solutions, and Tools