CVE-2026-11764
概要

When creating an export of all reusable media, the secrets of connected
gift cards were included in the export even if the user creating the
export does not have permission to view gift cards. This is inconsistent
with the UI and API where only the first letters of the gift card
secret are shown. Therefore, it allows circumventing a permission
boundary.

公表日 2026年6月9日22:16
登録日 2026年6月10日4:15
最終更新日 2026年6月9日22:57
関連情報、対策とツール
共通脆弱性一覧