Improper access control in Smart Content - CVE-2026-96386
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the Smart Content Block submodule does not sufficiently check block access when it renders the blocks of a "Display Blocks" reaction through the module's AJAX endpoint. A remote attacker can gain access to sensitive information on the system.