Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-02 12:17
Updated : 2026-09-04 03:17
NVD link : CVE-2026-84794
Mitre link : CVE-2026-84794
CVE.ORG link : CVE-2026-84794
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
