Path Traversal Vulnerability in Craft CMS by Craft
CVE-2026-32262
What is CVE-2026-32262?
Craft CMS, a well-known content management system, is susceptible to a path traversal vulnerability in its AssetsController->replaceFile() method. This flaw permits an authenticated user with 'replaceFiles' permission to manipulate the targetFilename parameter without proper sanitation. As a result, it enables the deletion of arbitrary files across different folders within the same filesystem root by injecting '../' sequences into file paths. This issue is significant for users with access to local filesystems and has been resolved in subsequent releases, specifically versions 4.17.5 and 5.9.11.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
cms >= 4.0.0-RC1, < 4.17.5 < 4.0.0-RC1, 4.17.5
cms >= 5.0.0-RC1, < 5.9.11 < 5.0.0-RC1, 5.9.11
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
