Server-Side Request Forgery Vulnerability in Craft CMS Versions 4.x and 5.x
CVE-2026-41129

5.5MEDIUM

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
21 April 2026

What is CVE-2026-41129?

Craft CMS, a popular content management system, has a vulnerability that allows for server-side request forgery. Specific versions in the 4.x branch up to 4.17.8 and the 5.x branch up to 5.9.14 are impacted. Exploitation of this vulnerability requires certain permissions to be enabled in the GraphQL schema, specifically 'Edit assets in the volume' and 'Create assets in the volume.' It is crucial for users operating affected versions to upgrade to 4.17.9 or 5.9.15, which address this security issue. For more information, please refer to the advisory and commit provided by Craft CMS.

Affected Version(s)

cms >= 5.0.0-RC1, < 5.9.15 < 5.0.0-RC1, 5.9.15

cms >= 4.0.0-RC1, < 4.17.9 < 4.0.0-RC1, 4.17.9

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.