CVE-2026-103476 Details
Description
yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished articles without authentication or authorization checks.
A vulnerability exists in Yii2 Starter Kit versions through 4.2.0, allowing unauthenticated users to download files from draft articles. This issue arises because the attachment-download endpoint does not properly validate the publication status of articles. Attackers can exploit this by sequentially enumerating attachment identifiers to access files from unpublished articles, bypassing authentication and authorization checks.
No specific remediation is provided, but developers should implement checks to ensure that only attachments from published articles can be accessed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/yii-starter-kit/yii2-starter-kit | [email protected] | ProductVendor |
| https://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/frontend/controllers/ArticleController.php#L69 | [email protected] | Source CodeVendor |
| https://github.com/yii-starter-kit/yii2-starter-kit/issues/797 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-unauthorized-file-download-via-attachment-download | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| yii2-starter-kit | <= 4.2.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion