Improperly Controlled Modification of Dynamically-Determined Object Attributes in Craft CMS - CVE-2026-28781
Published: June 16, 2026
Craft CMS
Detailed vulnerability description
The vulnerability allows a remote user to spoof entry authorship.
The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the entry creation process when handling crafted POST requests. A remote user can add the authorId or authorIds[] parameter to a request to spoof entry authorship.
Exploitation requires an account with permission to create entries and knowledge of the target user's account ID.