{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/craft-cms--5.10.11/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-84794"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Craft CMS (\u003c 5.10.11)","Craft CMS (\u003e= 5.0.0-RC1, \u003c 5.10.11)","Craft CMS (5.0.0-RC1 to 5.10.10)"],"_cs_severities":["high"],"_cs_tags":["cms","web-vulnerability","authorization-bypass","web-application","vulnerability","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["Craft CMS"],"content_html":"\u003cp\u003eCraft CMS versions before 5.10.11 are vulnerable to an authorization bypass vulnerability (CVE-2026-84794) within the assets/move-asset endpoint. The vulnerability arises when an authenticated user, even without the necessary peer asset permissions, submits a specifically crafted request to move an asset. By supplying the 'force=1' parameter, the attacker can manipulate the move operation to target folders owned by other users. This action can force the deletion of conflicting files already present in the target destination, leading to unauthorized asset replacement and permanent data loss. This flaw highlights a failure in the application's access control logic regarding asset management operations. Organizations utilizing Craft CMS 5.x should upgrade to version 5.10.11 or later to remediate this vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated, low-privileged users to perform unauthorized asset management actions. This results in the potential destruction of data, modification of content, and the ability to replace files within other users' folders, which can disrupt site operations and compromise data integrity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Craft CMS to version 5.10.11 or later immediately.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous POST requests to the 'assets/move-asset' endpoint.\u003c/li\u003e\n\u003cli\u003eAudit user permissions to ensure that only authorized users possess the necessary privileges for asset management.\u003c/li\u003e\n\u003cli\u003eDeploy the provided web application detection rule to identify attempts to trigger the vulnerable endpoint with the force parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T13:14:24Z","date_published":"2026-09-02T13:13:44Z","id":"https://feed.craftedsignal.io/briefs/2026-09-craft-cms-auth-bypass/","summary":"Craft CMS versions prior to 5.10.11 contain an authorization bypass in the assets/move-asset endpoint, allowing authenticated users with insufficient permissions to move and delete arbitrary assets by supplying the force=1 parameter.","title":"Authorization Bypass in Craft CMS assets/move-asset Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-09-craft-cms-auth-bypass/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pixelandtonic:craft_cms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-84795"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Craft CMS (\u003c 5.10.11)"],"_cs_severities":["critical"],"_cs_tags":["cve-2026-84795","privilege-escalation","cms"],"_cs_type":"advisory","_cs_vendors":["Pixel \u0026 Tonic"],"content_html":"\u003cp\u003eCraft CMS versions before 5.10.11 are vulnerable to an unauthorized privilege escalation flaw (CVE-2026-84795). The vulnerability arises because the system fails to correctly validate or clear the 'admin' flag when a user registers, specifically if they register with an email address previously associated with a deactivated administrator account.\u003c/p\u003e\n\u003cp\u003eThis issue is exploitable only under specific configuration scenarios: when public user registration is enabled and email verification is disabled. If these conditions are met, an attacker can register an account using the known email address of a deactivated admin. The application incorrectly maps the new registration to the existing, albeit deactivated, record's administrative privileges, resulting in full unauthorized access. This flaw represents a critical security risk as it bypasses standard access control mechanisms. Defenders must ensure that public registration is limited or strictly monitored and that email verification is enforced to prevent this vector.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain full administrative control over the Craft CMS instance. This can lead to total system compromise, unauthorized data exfiltration, and persistent access to the back-end administrative interface. This vulnerability affects all Craft CMS installations configured with public registration and disabled email verification running versions prior to 5.10.11.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Craft CMS to version 5.10.11 or later immediately to address CVE-2026-84795.\u003c/li\u003e\n\u003cli\u003eReview administrative account configurations to ensure that deactivated accounts are properly purged or restricted.\u003c/li\u003e\n\u003cli\u003eDisable public user registration on all production Craft CMS instances unless explicitly required.\u003c/li\u003e\n\u003cli\u003eEnsure that email verification is strictly enabled for all user registration flows to mitigate unauthorized account takeovers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T13:13:33Z","date_published":"2026-09-02T13:13:33Z","id":"https://feed.craftedsignal.io/briefs/2026-09-02-craft-cms-privilege-escalation/","summary":"Craft CMS versions prior to 5.10.11 contain a vulnerability allowing unauthenticated attackers to inherit administrator privileges by registering with the email address of a deactivated admin account when specific registration settings are active.","title":"Privilege Escalation in Craft CMS via Registration Flaw","url":"https://feed.craftedsignal.io/briefs/2026-09-02-craft-cms-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Craft CMS (\u003c 5.10.11)","version":"https://jsonfeed.org/version/1.1"}