CVE-2026-21626
Severity CVSS v4.0:
CRITICAL
Type:
CWE-200
Information Leak / Disclosure
Publication date:
06/02/2026
Last modified:
06/02/2026
Description
Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure
Impact
Base Score 4.0
9.20
Severity 4.0
CRITICAL



