Authorization Bypass Vulnerability in Craft CMS by Craft
CVE-2026-56385
5.3MEDIUM
What is CVE-2026-56385?
Craft CMS versions from 5.0.0-RC1 to 5.9.13 and 4.0.0-RC1 to 4.17.7 are susceptible to an authorization bypass in the assets/preview-file endpoint. This flaw allows an authenticated low-privileged user to manipulate the assetId parameter, gaining access to preview data for assets they are not authorized to view. The vulnerability enables the potential exposure of sensitive preview content, including private image routes. The issue has been resolved in versions 5.9.14 and 4.17.8, emphasizing the importance of updating affected installations promptly.
Affected Version(s)
cms 5.0.0-RC1 < 5.9.14
cms 4.0.0-RC1 < 4.17.8
cms 5.9.14
