Information Disclosure in Craft CMS by Craft
CVE-2026-44012

7.1HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-44012?

Craft CMS suffers from a significant information disclosure vulnerability where the AssetsController::actionShowInFolder() function allows any authenticated control panel (CP) user to retrieve asset filenames and the complete folder hierarchy of any volume without proper permission checks. This means that users with no permissions to view specific assets can still enumerate through asset IDs, potentially exposing sensitive information stored within the Craft CMS environment. This vulnerability has been patched in version 5.9.18, and users are advised to upgrade their installations promptly to mitigate this risk.

Affected Version(s)

cms >= 5.0.0-RC1, < 5.9.18

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.