Missing Authorization in Craft CMS - #VU144284

 

Missing Authorization in Craft CMS - #VU144284

Published: August 19, 2026


Vulnerability identifier: #VU144284
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in AssetsController::actionMoveInfo when handling crafted control panel POST requests with arbitrary folderIds or assetIds. A remote user can send a specially crafted request to disclose sensitive information.

The issue leaks aggregate metadata including asset count and total storage size across folders or volumes the user cannot view, but does not expose file contents or filenames.


Affected software

Craft CMS

Remediation

Install security update from vendor's website.

Craft CMS - update to 5.10.12

External References

Related Security Bulletins