Cross-site request forgery in Craft CMS - CVE-2026-29113
Published: June 16, 2026
Craft CMS
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the preview token endpoint when handling crafted cross-site requests to create preview tokens. A remote attacker can trick a logged-in victim into sending a crafted request to disclose sensitive information.
Exploitation requires the victim to be logged in and have active preview authorization in session for the targeted content.