CVE-2026-81892 | EasyCorp EasyAdminBundle up to 4.29.15/5.5.0 Route Swapping linkToRoute routeName improper authorization

SecurityVulns

A vulnerability, which was classified as critical, was found in EasyCorp EasyAdminBundle up to 4.29.15/5.5.0. Affected is the function Action::linkToRoute/MenuItem::linkToRoute of the component Route Swapping. Executing a manipulation of the argument routeName can lead to improper authorization.

This vulnerability is tracked as CVE-2026-81892. The attack can be launched remotely. No exploit exists.

You should upgrade the affected component.VulDB Recent EntriesRead More