Missing Authorization Vulnerability in Craft CMS AssetsController
CVE-2026-84800
7.1HIGH
What is CVE-2026-84800?
Craft CMS versions from 5.0.0-RC1 up to, but not including, 5.10.11 have a missing authorization vulnerability in the AssetsController. This occurs when a request to replace an asset file is made without providing the necessary assetId, allowing the system to resolve the target asset based solely on the folder and filename. As a result, the permissions to enforce replacement are bypassed, enabling a low-privilege authenticated user to overwrite a peer's asset file in the same folder with malicious content. This vulnerability was addressed in version 5.10.11.
Affected Version(s)
cms 5.0.0-RC1 < 5.10.11
cms 5.10.11
