CVE-2026-84794

HIGH
7.1CVSS v3
CVSS v2
0.20% EPSS (exploit probability)
CWE-862CWE

Description

Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references