Any user (including an anonymous user) can bypass APIv4 permission checks with a specially crafted REST call.
Discussion: This is a variation of CIVI-SA-2026-35. The original fix for CIVI-SA-2026-35 was narrowly framed to minimize regression-risk; but this allowed similar bugs to remain in other code-paths. The new patch for CIVI-SA-2026-37 is more aggressive. Consequently, it closes off more variations on the bug.

