Unauthorized Entry Movement in Craft CMS by Vendor Craft
CVE-2026-33162
4.9MEDIUM
What is CVE-2026-33162?
In Craft CMS, an authenticated control panel user with limited permissions can manipulate entry movement across sections via a specific POST request. This flaw permits users without adequate rights to move entries even when they should not possess such access. The vulnerability existed in versions 5.3.0 through 5.9.13 and has been addressed in the release of version 5.9.14.
Affected Version(s)
cms >= 5.3.0, < 5.9.14
