CVE-2026-28696 | Craft CMS prior 4.17.0-beta.1/5.9.0-beta.1 GraphQL Directive Elements::parseRefs authorization
A vulnerability classified as problematic was found in Craft CMS. Affected is the function Elements::parseRefs of the component GraphQL Directive Handler. Executing a manipulation can lead to authorization bypass.
The identification of this vulnerability is CVE-2026-28696. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.