CVE-2026-97070
CozyThemes Cozy Blocks
Published 5 Oct 2026 · updated 5 Oct 2026 · Received
6.9 Medium · CVSS 4.0, patchstack.com
Description
Authorization Bypass Through User-Controlled Key vulnerability in CozyThemes Cozy Blocks cozy-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cozy Blocks: from n/a through 2.2.23.