{"id":"CVE-2026-103476","summary":"yii2-starter-kit through 4.2.0 Unauthorized File Download via attachment-download","details":"yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished articles without authentication or authorization checks.","modified":"2026-10-03T03:30:52.598825437Z","published":"2026-09-30T17:22:42.463Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-639"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103476.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103476.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103476"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-unauthorized-file-download-via-attachment-download"},{"type":"REPORT","url":"https://github.com/yii-starter-kit/yii2-starter-kit/issues/797"},{"type":"PACKAGE","url":"https://github.com/yii-starter-kit/yii2-starter-kit"},{"type":"ARTICLE","url":"https://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/frontend/controllers/ArticleController.php#L69"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/yii-starter-kit/yii2-starter-kit","events":[{"introduced":"0"},{"fixed":"cc2c451e8c959c7300b04efea597706a38609f58"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION"],"extracted_events":[{"introduced":"0"},{"last_affected":"4.2.0"},{"introduced":"yii2-starter-kit"},{"fixed":"4.2.0"}]}}],"versions":["4.1.0","4.0.0","3.0.3","v3.0.2","3.0.1","3.0.0","2.6.0","2.5.2","2.5.1","2.5.0","2.3.2","2.3.1","2.3.0","2.2.2","2.2.1","2.2.0","2.1.3","2.1.2","2.1.1","2.1.0","2.0.2","2.0.1","2.0.0","1.5.1","1.5.0","1.4.3","1.4.2","1.4.1","1.4.0","1.3.0","1.2.0","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103476.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}