A vulnerability, which was classified as critical, was found in EasyCorp EasyAdminBundle up to 4.29.15/5.5.0. Affected is the function Action::linkToRoute/MenuItem::linkToRoute of the component Route Swapping. Executing a manipulation of the argument routeName can lead to improper authorization. This vulnerability is tracked as CVE-2026-81892. The attack can be launched remotely. No exploit exist
Vulnerability
CVE-2026-81892
VulDB
Apply vendor security patch