Skip to content

Unauthenticated front-end submission editing can overwrite existing submissions

High
engram-design published GHSA-pgxq-p76c-x9cg May 19, 2026

Package

composer verbb/formie (Composer)

Affected versions

< 3.1.26
< 2.2.21

Patched versions

3.1.26
2.2.21

Description

Impact

Unauthenticated users could modify existing submissions by posting a known or guessed submission ID to formie/submissions/save-submission.

Patches

2.2.21, 3.1.26

Workarounds

Block unauthenticated access to actions/formie/submissions/save-submission, or disable/customize front-end submission editing until patched.

Credit

Many thanks to:

Severity

High

CVE ID

CVE-2026-47266

Weaknesses

Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data. Learn more on MITRE.