HIGH
puemos
CVE published 2026-08-21
CVE-2026-76876
Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sensitive credentials. The vulnerability is caused by an unconditional authorization policy on the Settings resource, which enables attackers to send a GET request to the settings API endpoint with a valid record ID to retrieve decrypted SMTP passwords, email API keys, and email API secrets. [truncated]