Skip to content
Threat Feed
high advisory

Authorization Bypass in Craft CMS assets/move-asset Endpoint

Craft CMS versions prior to 5.10.11 contain an authorization bypass in the assets/move-asset endpoint, allowing authenticated users with insufficient permissions to move and delete arbitrary assets by supplying the force=1 parameter.

CVE search metadata

CVE search record: CVE-2026-84794. Severity: high. CVSS: 7.1. KEV: no. Product: Craft CMS (< 5.10.11), Craft CMS (>= 5.0.0-RC1, < 5.10.11), Craft CMS (5.0.0-RC1 to 5.10.10). Brief: Authorization Bypass in Craft CMS assets/move-asset Endpoint. Brief link: https://feed.craftedsignal.io/briefs/2026-09-craft-cms-auth-bypass/

What's new

  • 1. added coverage for Craft CMS (< 5.10.11) Sep 2, 13:14 via nvd
  • 2. added coverage for Craft CMS (5.0.0-RC1 to 5.10.10) Sep 2, 13:14 via nvd
  • 3. added coverage for Craft CMS (>= 5.0.0-RC1, < 5.10.11) Sep 2, 13:14 via nvd
  • 4. added coverage for Craft CMS (< 5.10.11) Sep 2, 13:13 via nvd

Craft CMS versions before 5.10.11 are vulnerable to an authorization bypass vulnerability (CVE-2026-84794) within the assets/move-asset endpoint. The vulnerability arises when an authenticated user, even without the necessary peer asset permissions, submits a specifically crafted request to move an asset. By supplying the 'force=1' parameter, the attacker can manipulate the move operation to target folders owned by other users. This action can force the deletion of conflicting files already present in the target destination, leading to unauthorized asset replacement and permanent data loss. This flaw highlights a failure in the application's access control logic regarding asset management operations. Organizations utilizing Craft CMS 5.x should upgrade to version 5.10.11 or later to remediate this vulnerability.

Impact

Successful exploitation allows authenticated, low-privileged users to perform unauthorized asset management actions. This results in the potential destruction of data, modification of content, and the ability to replace files within other users' folders, which can disrupt site operations and compromise data integrity.

Recommendation

  • Upgrade all instances of Craft CMS to version 5.10.11 or later immediately.
  • Review web server access logs for anomalous POST requests to the 'assets/move-asset' endpoint.
  • Audit user permissions to ensure that only authorized users possess the necessary privileges for asset management.
  • Deploy the provided web application detection rule to identify attempts to trigger the vulnerable endpoint with the force parameter.

Immediate actions

Upgrade Craft CMS to version 5.10.11 or later.

IT Operations 48h

Mitigations

Patch Craft CMS to 5.10.11.

immediate IT Operations

CVE-2026-84794

Detection coverage 1

Detects CVE-2026-84794 Exploitation - Unauthorized Asset Move Request

high

Detects POST requests to the assets/move-asset endpoint containing the force=1 parameter, which may indicate an attempt to exploit the authorization bypass vulnerability.

sigma tactics: privilege_escalation techniques: T1068 sources: webserver

Detection queries are available on the platform. Get full rules →