Information Disclosure in Craft CMS by Craft
CVE-2026-44012
7.1HIGH
What is CVE-2026-44012?
Craft CMS suffers from a significant information disclosure vulnerability where the AssetsController::actionShowInFolder() function allows any authenticated control panel (CP) user to retrieve asset filenames and the complete folder hierarchy of any volume without proper permission checks. This means that users with no permissions to view specific assets can still enumerate through asset IDs, potentially exposing sensitive information stored within the Craft CMS environment. This vulnerability has been patched in version 5.9.18, and users are advised to upgrade their installations promptly to mitigate this risk.
Affected Version(s)
cms >= 5.0.0-RC1, < 5.9.18
