CVE-2026-103476 | yii-starter-kit yii2-starter-kit up to 4.2.0 Attachment Download Endpoint improper authorization

SecurityVulns

A vulnerability identified as problematic has been detected in yii-starter-kit yii2-starter-kit up to 4.2.0. Affected is an unknown function of the component Attachment Download Endpoint. Performing a manipulation results in improper authorization.

This vulnerability was named CVE-2026-103476. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More