CVE-2026-32267Incorrect Authorization in Craft CMS

Severity
7.7HIGHNVD
EPSS
0.0%
top 88.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 16

Description

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their privileges to admin by abusing UsersController->actionImpersonateWithToken. This issue has been patched in versions 4.17.6 and 5.9.12.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages3 packages

Packagistcraftcms/cms4.0.0-RC14.17.6+1
NVDcraftcms/craft_cms4.0.0.14.17.6+3
CVEListV5craftcms/cms>= 4.0.0-RC1, < 4.17.6, >= 5.0.0-RC1, < 5.9.12+1

Patches

🔴Vulnerability Details

3
CVEList
Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()2026-03-16
OSV
Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()2026-03-16
GHSA
Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()2026-03-16

🕵️Threat Intelligence

1
Wiz
CVE-2026-32267 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-32267 — Incorrect Authorization in Craft CMS | cvebase