{"id":"CVE-2026-103476","title":"yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles","summary":"yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment iden…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-639"],"vendor":"yii2-starter-kit","product":"yii2-starter-kit","affected":["yii2-starter-kit <= 4.2.0"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T19:08:43.927","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103476","references":[{"url":"https://github.com/yii-starter-kit/yii2-starter-kit","label":"disclosure@vulncheck.com"},{"url":"https://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/frontend/controllers/ArticleController.php#L69","label":"disclosure@vulncheck.com"},{"url":"https://github.com/yii-starter-kit/yii2-starter-kit/issues/797","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-unauthorized-file-download-via-attachment-download","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T18:17:24.546Z","slug":"CVE-2026-103476","body":"## Overview\n\nyii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished articles without authentication or authorization checks.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}