Improper Authorization in Craft CMS - #VU144281
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper authorization in native GraphQL element-to-user relations when resolving related user fields through GraphQL queries. A remote user can query author, authors, uploader, draftCreator, or revisionCreator fields to disclose sensitive information.
The issue affects user-group scoping for related user records and can expose usernames, email addresses, and full names outside the intended GraphQL schema scope.