CVE-2026-103476
Received Received - Intake

Unauthenticated File Download in Yii2 Starter Kit

Vulnerability report for CVE-2026-103476, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished articles without authentication or authorization checks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yii-starter-kit yii2-starter-kit to 4.2.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in yii2-starter-kit through version 4.2.0 allows unauthenticated attackers to download files from draft articles by exploiting an unprotected attachment-download endpoint. The system fails to check if an article is published before allowing file access, enabling sequential attachment ID guessing to retrieve unpublished files without authentication.

Detection Guidance

Check if your yii2-starter-kit version is 4.2.0 or below by inspecting the composer.lock file or running composer show yii2-starter-kit. Look for unauthorized file downloads by monitoring access logs for the attachment-download endpoint and checking for sequential attachment ID requests.

Impact Analysis

Attackers could access sensitive files from unpublished articles, including drafts, internal documents, or confidential attachments. This may lead to data leaks, intellectual property theft, or compliance violations depending on the exposed content.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data in draft articles or HIPAA by leaking protected health information. Unauthorized access to sensitive data may result in regulatory fines, legal liabilities, and reputational damage due to non-compliance with data protection requirements.

Mitigation Strategies

Upgrade yii2-starter-kit to a version higher than 4.2.0 immediately. If upgrading is not possible, implement strict validation in the attachment-download endpoint to verify article publication status and restrict file access to authorized users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103476. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart