createPuckPlugin of the component CRUD Endpoint. This manipulation causes missing authorization.This vulnerability is handled as CVE-2026-39397. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.