CVE-2026-76089: Formie: Missing authorization on sent notification resend modal exposes submission PII

Published Sep 23, 2026
·
Updated

Impact

The control panel action formie/sent-notifications/get-resend-modal-content (SentNotificationsController::actionGetResendModalContent) performed only requireAcceptsJson() and loaded a SentNotification by request id without permission or object-level authorization checks.

Any authenticated user who could invoke the action could enumerate notification IDs and read full email content — including recipient headers and the complete HTML body containing submitted form data (PII) — without formie-accessSentNotifications or equivalent permission. Sibling actions in the same controller enforced authorization.

Patches

Fixed in 3.1.31 (Craft 5) and 2.2.23 (Craft 4).

Craft 5: canView() is enforced after loading, consistent with actionEdit. Craft 4: formie-viewSentNotifications permission is required.

Workarounds

Restrict CP access to trusted users only until upgraded. No configuration workaround.

- Reported by Jorge González (jorge@jmilla.es)

Other sources

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs and read recipient headers and complete HTML email bodies containing submitted form data, even without the sent-notification viewing permission. This issue is fixed in versions 2.2.23 and 3.1.31.

MITRE

Affected Software

3 affected componentsFixes available
verbb Formie<2.2.23, <3.1.31
composer/verbb/formie<2.2.23
2.2.23
composer/verbb/formie>=3.0.0<3.1.31
3.1.31

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/verbb/formie to a version that resolves this vulnerability.

    Fixed in 2.2.23
  2. Upgrade

    Upgrade composer/verbb/formie to a version that resolves this vulnerability.

    Fixed in 3.1.31
  3. Upgrade

    Upgrade Formie for Craft 4 to a version that resolves this vulnerability.

    Fixed in 2.2.23
  4. Upgrade

    Upgrade Formie for Craft 5 to a version that resolves this vulnerability.

    Fixed in 3.1.31
  5. Compensating control

    Restrict control panel access to trusted users only until Formie is upgraded.

Event History

Sep 23, 2026
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:24 PM
Data Sourced
via GitHub·09:24 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which users are exposed to this issue?

Any authenticated user who can invoke the affected control panel action may be able to exploit it. The user does not need the sent-notification viewing permission.

2

What information could be disclosed?

An attacker can enumerate notification IDs and retrieve recipient headers and complete HTML email bodies. Those email bodies can contain submitted form data and other submission PII.

3

What access does an attacker need?

The attacker needs an authenticated account and the ability to invoke the affected control panel action. No user interaction is required.

4

Which versions contain the fix?

The issue is fixed in Formie versions 2.2.23 and 3.1.31. Versions before those releases are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203