Loading market data...
← Back to CVE feed

CVE-2026-84794

HIGH CVSS 7.1 View on NVD ↗

Description

Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Published: Sep 02, 2026 12:17 UTC Modified: Sep 02, 2026 13:54 UTC