LIVE · cybersecurity feed
Live wire
cve record

CVE-2026-23923

Published
CVSS—
Severitynone
WeaknessCWE-470
ExploitedNot in CISA KEV

Description

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-23923

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-23923.