Cross-site request forgery in Craft CMS - CVE-2026-29113

 

Cross-site request forgery in Craft CMS - CVE-2026-29113

Published: June 16, 2026


Vulnerability identifier: #VU134660
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-29113
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the preview token endpoint when handling crafted cross-site requests to create preview tokens. A remote attacker can trick a logged-in victim into sending a crafted request to disclose sensitive information.

Exploitation requires the victim to be logged in and have active preview authorization in session for the targeted content.


Affected software

Craft CMS

How to mitigate CVE-2026-29113

Install security update from vendor's website.

Craft CMS - addressed in versions 4.17.4, 5.9.7

External References

Related Security Bulletins