CVE-2026-84794

Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 12:17

Updated : 2026-09-04 03:17


NVD link : CVE-2026-84794

Mitre link : CVE-2026-84794

CVE.ORG link : CVE-2026-84794


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization