← Back to overview

Craft CMS versions prior to 5.10.11 contain a critical authorization bypass vulnerability in the assets/move-asset endpoint. When the force=1 parameter is supplied, the endpoint fails to perform proper authorization checks. Authenticated users who lack peer asset permissions can exploit this flaw to move their own assets into other users' folders. The force parameter additionally triggers deletion of conflicting files, enabling unauthorized asset deletion and replacement. This affects a wide range of Craft CMS 5.x installations up to and including version 5.10.10. The vulnerability requires authentication but does not require elevated privileges beyond a standard user account. It poses risks of data loss, content tampering, and potential disruption to web applications relying on the CMS asset management system. A fix has been issued in version 5.10.11. Advisories have been published by both the Craft CMS GitHub security team and VulnCheck.

Affected products

  • Craft CMS 5.0.0 through 5.10.10

Related CVE's

  • CVE-2026-84794

Categories

  • Enterprise Applications
  • Identity & Access
  • Web Technologies