CVE-2026-107856 | CiviForm up to 3.32.x Trusted Intermediary editClientForm showEditClientForm accountId authorization

SecurityVulns

A vulnerability classified as problematic has been found in CiviForm up to 3.32.x. Affected by this vulnerability is the function showEditClientForm of the file /admin/tiDash/editClientForm of the component Trusted Intermediary. The manipulation of the argument accountId leads to authorization bypass.

This vulnerability is traded as CVE-2026-107856. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More