CVE-2026-27591 | Winter CMS up to 1.0.476/1.1.11/1.2.11 Requests access control (GHSA-pgpf-m8m4-6cg6)
A vulnerability identified as critical has been detected in Winter CMS up to 1.0.476/1.1.11/1.2.11. Affected by this vulnerability is an unknown functionality of the component Requests Handler. Performing a manipulation results in improper access controls.
This vulnerability is known as CVE-2026-27591. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.