Improper access control in Craft CMS - CVE-2026-28696
Published: June 16, 2026
Craft CMS
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the GraphQL `@parseRefs` directive and `craft\services\Elements::parseRefs` when parsing user-supplied internal reference tags in GraphQL content. A remote user can inject a crafted reference tag to disclose sensitive information.
Unauthenticated exploitation is possible if a Public Schema is enabled.