CVE-2020-26136: Silverstripe

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.

Affected products

  • Silverstripe Silverstripe: before 4.6.0 (fixed in 4.6.0); version 4.6.0 only

Published 2021-06-08. Last modified 2026-06-17.