form_settings_ui of the file add_cap/remove_cap of the component Setting Handler. Executing a manipulation can lead to cross-site request forgery.This vulnerability is handled as CVE-2026-9732. The attack can be executed remotely. There is not any exploit available.