Missing Authorization in Craft CMS - #VU139962
Published: July 29, 2026
Vulnerability details
The vulnerability allows a remote user to reorder all global sets.
The vulnerability exists due to improper access control in the GlobalsController reorder-sets action when handling POST requests to /actions/globals/reorder-sets. A remote user can send a crafted POST request to reorder all global sets.
The change is written to the project configuration and persists across requests.