Improper access control in Combined image style - CVE-2026-96377
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected module does not sufficiently validate image style names when generating image derivatives. A remote attacker can generate image derivatives without a valid token and perform a denial of service (DoS) attack.