CVE-2026-84794
published 2026-09-02CVE-2026-84794: Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset…
PriorityP339high7.1CVSS 3.1
AVNACLPRLUINSUCNIHAL
EPSS
0.20%
10.2th percentile
Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| craftcms | cms | >= 5.0.0-RC1 < 5.10.11 | 5.10.11 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
nvdv4.07.1HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Craft CMS up to 5.10.10 Move Asset force incorrect user management (CNNVD-2026-98808391)
vuldb·2026-09-04·CVSS 7.1
CVE-2026-84794 [HIGH] Craft CMS up to 5.10.10 Move Asset force incorrect user management (CNNVD-2026-98808391)
A vulnerability has been found in Craft CMS up to 5.10.10 and classified as problematic. This affects an unknown function of the component Move Asset. This manipulation of the argument force causes incorrect user management.
This vulnerability is registered as CVE-2026-84794. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
GHSA
Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied.
ghsa_unreviewed·2026-09-02
CVE-2026-84794 [HIGH] CWE-862 Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied.
Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-02
Published