Missing Authorization Vulnerability in Craft CMS AssetsController
CVE-2026-84800

7.1HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84800?

Craft CMS versions from 5.0.0-RC1 up to, but not including, 5.10.11 have a missing authorization vulnerability in the AssetsController. This occurs when a request to replace an asset file is made without providing the necessary assetId, allowing the system to resolve the target asset based solely on the folder and filename. As a result, the permissions to enforce replacement are bypassed, enabling a low-privilege authenticated user to overwrite a peer's asset file in the same folder with malicious content. This vulnerability was addressed in version 5.10.11.

Affected Version(s)

cms 5.0.0-RC1 < 5.10.11

cms 5.10.11

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.