Summary
Winter: Authenticated backend users can bypass Users controller permission checks
Workarounds
If users cannot upgrade, they may apply the following changes to their Winter CMS installation manually to resolve this issue:
- In
modules/backend/classes/Controller.php, validate the_handlerPOST field against theon[A-Z][\w+]*pattern before passing it torunAjaxHandler(). - In
modules/backend/controllers/Users.php, remove the conditional that sets$requiredPermissionstonullfor themyaccountaction.
Impact
Affected versions of Winter CMS did not validate the handler name submitted through the form postback mechanism (_handler POST field) in the same way as AJAX requests (X_WINTER_REQUEST_HANDLER header). The AJAX path validates that handler names match the on[A-Z][\w+]* pattern, but the postback path passed the handler name directly to the handler dispatcher with no validation.
This allowed an authenticated backend user to call any method on a controller, including action-prefixed, protected, and private methods, by submitting a crafted POST request with a _handler field, as long as the controller either:
- Contains a publicly available action via the
$publicActionsproperty, or - Degrades or removes the
$requiredPermissionscheck in its constructor based on a condition
The backend's own Users controller was affected by the second scenario: it set $requiredPermissions to null for the myaccount action, allowing any authenticated backend user to access the controller without the backend.manage_users permission. Combined with the postback bypass, this allowed calling controller methods such as update_onDelete, update_onRestore, update_onUnsuspendUser, and update_onManualPasswordReset with attacker-controlled parameters.
Note that CSRF tokens are still verified on all POST requests, so the attacker must be logged into the backend with a valid session.
To actively exploit this security issue, an attacker would need access to the Backend with a user account with any level of access.
The Winter CMS maintainers strongly recommend that all Winter CMS sites that have any reliance on the roles & permissions system to update immediately. Security fixes have been backported to all major versions of Winter (1.0, 1.1, and 1.2).
Affected versions
Security releases
Kodem intelligence
Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.
Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.
Already deployed Kodem?
See it in your environmentNew to Kodem? Get a demo →Remediation advice
The postback handler path now validates handler names using the same rules as the AJAX path. The My Account functionality has been moved to a dedicated controller that does not expose user management methods. Defence in depth has been applied at the model level to prevent unauthorized user record modifications regardless of the entry point.
This security issue has been fixed as of v1.2.13.
Frequently Asked Questions
- What is CVE-2026-35445? CVE-2026-35445 is a high-severity security vulnerability in winter/wn-backend-module (composer), affecting versions <= 1.2.12. It is fixed in 1.2.13.
- Which versions of winter/wn-backend-module are affected by CVE-2026-35445? winter/wn-backend-module (composer) versions <= 1.2.12 is affected.
- Is there a fix for CVE-2026-35445? Yes. CVE-2026-35445 is fixed in 1.2.13. Upgrade to this version or later.
- Is CVE-2026-35445 exploitable, and should I be worried? Whether CVE-2026-35445 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
- What actually determines whether CVE-2026-35445 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
- How do I fix CVE-2026-35445? Upgrade
winter/wn-backend-moduleto 1.2.13 or later.