Product
high
advisory
Authorization Bypass in Craft CMS assets/move-asset Endpoint
1 rule 3 TTPs 1 CVECraft CMS versions prior to 5.10.11 contain an authorization bypass in the assets/move-asset endpoint, allowing authenticated users with insufficient permissions to move and delete arbitrary assets by supplying the force=1 parameter.
Craft CMS +2
cms
web-vulnerability
authorization-bypass
web-application
vulnerability
privilege-escalation
1r
3t
1c
critical
advisory
Privilege Escalation in Craft CMS via Registration Flaw
1 TTP 1 CVECraft CMS versions prior to 5.10.11 contain a vulnerability allowing unauthenticated attackers to inherit administrator privileges by registering with the email address of a deactivated admin account when specific registration settings are active.
Craft CMS
cve-2026-84795
privilege-escalation
cms
1t
1c