PatchSiren

puemos CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH puemos CVE published 2026-08-21

CVE-2026-76876

Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sensitive credentials. The vulnerability is caused by an unconditional authorization policy on the Settings resource, which enables attackers to send a GET request to the settings API endpoint with a valid record ID to retrieve decrypted SMTP passwords, email API keys, and email API secrets. [truncated]