Missing Authorization in Craft CMS - #VU144276
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to delete and replace another user\'s asset.
The vulnerability exists due to improper access control in assets/move-asset when handling requests with force=1. A remote user can send a specially crafted request to delete and replace another user\'s asset.
Exploitation requires an authenticated Control Panel user who can manage their own assets in a volume but lacks peer asset permissions, and is limited to assets in the same volume with a conflicting filename.