CVE-2026-21626

Severity CVSS v4.0:
CRITICAL
Type:
CWE-200 Information Leak / Disclosure
Publication date:
06/02/2026
Last modified:
06/02/2026

Description

Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure

References to Advisories, Solutions, and Tools