Missing Authorization in Craft CMS - CVE-2026-44012

 

Missing Authorization in Craft CMS - CVE-2026-44012

Published: June 16, 2026


Vulnerability identifier: #VU134672
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44012
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in AssetsController::actionShowInFolder() when handling control panel requests for asset IDs. A remote user can supply an arbitrary asset ID to disclose sensitive information.

The issue exposes asset filenames and complete folder hierarchy details, including volume handles, volume UIDs, folder names, folder UIDs, and folder URI paths.


Affected software

Craft CMS

How to mitigate CVE-2026-44012

Install security update from vendor's website.

Craft CMS - update to 5.9.18

External References

Related Security Bulletins