Authorization Bypass Vulnerability in Craft CMS by Craft
CVE-2026-56385

5.3MEDIUM

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
21 June 2026

What is CVE-2026-56385?

Craft CMS versions from 5.0.0-RC1 to 5.9.13 and 4.0.0-RC1 to 4.17.7 are susceptible to an authorization bypass in the assets/preview-file endpoint. This flaw allows an authenticated low-privileged user to manipulate the assetId parameter, gaining access to preview data for assets they are not authorized to view. The vulnerability enables the potential exposure of sensitive preview content, including private image routes. The issue has been resolved in versions 5.9.14 and 4.17.8, emphasizing the importance of updating affected installations promptly.

Affected Version(s)

cms 5.0.0-RC1 < 5.9.14

cms 4.0.0-RC1 < 4.17.8

cms 5.9.14

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

GCXWLP
.