How to use this reference
The two branch-specific patches require control-panel request context, a valid form and integration permission, then limit mutable settings while excluding destination and credential properties. Editorial lesson: operation authorization and attribute authority are complementary controls; possessing an authenticated session does not establish either. Review alternate entry points after a shared permission repair. The official releases identify 2.2.23 for Craft 4 and 3.1.31 for Craft 5 as patched.
Before reading
- Distinguishing authentication from operation-specific authorization
- Understanding settings mutation and credential-bearing integration requests
Context and limits
- The described case requires an affected installation and an authenticated caller, including a front-end member; credential impact additionally depends on a configured integration holding credentials.
- The advisory identifies incomplete earlier authorization remediation. Temporary restrictions on registration and control-panel access are not a complete configuration-only fix.
- The reviewed sources provide no controlled test transcript, production incident, victim count or independent reproduction. Downstream account takeover or cloud compromise is not established. No individual award is established.
- The advisory body credits Jorge González as reporter; its formal credit lists Pig-Tail as Finder. Their identity relationship is not established here. engram-design is the publishing account, not an explicit narrative byline, so authors remains empty.
- The GitHub database records its own publication and review on September 23, 2026. The official release APIs give July 9, 2026 at 12:21:35 UTC for 2.2.23 and 12:26:02 UTC for 3.1.31. Software release, advisory publication, database entry, educational edition and installation-specific deployment are separate events; deployment dates remain unknown.
Sources and provenance
- Formie integration-settings security advisory Verbb / Formie · reviewed 2026-10-04
- GitHub Advisory Database entry for CVE-2026-76086 GitHub · reviewed 2026-10-04
- Formie Craft 4 integration authorization and settings restriction patch Verbb / Formie · reviewed 2026-10-04
- Formie Craft 5 integration authorization and settings restriction patch Verbb / Formie · reviewed 2026-10-04
- Official Formie 2.2.23 release metadata Verbb / Formie · reviewed 2026-10-04
- Official Formie 3.1.31 release metadata Verbb / Formie · reviewed 2026-10-04
Record reviewed 2026-10-04. Snapshot d5550c789111. Open the complete JSON contract.