PT-2026-51232 · Craft Cms · Craft Cms

·

CVE-2026-56384

·

Published

2026-06-21

·

Updated

2026-07-06

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Craft CMS versions 4.0.0-RC1 through 4.17.7 Craft CMS versions 5.0.0-RC1 through 5.9.13
Description A missing authorization issue exists in the 'assets/preview-thumb' endpoint. A Control Panel user lacking permissions to view a specific private asset can provide a controlled assetId to the endpoint. This allows the user to receive preview HTML containing a signed fallback transform preview link for that private asset, as the system fails to perform an asset-view permission check before generating the preview.
Recommendations Update to version 4.17.8 for versions in the 4.x branch. Update to version 5.9.14 for versions in the 5.x branch.

Exploit

Fix

Information Disclosure

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56384
GHSA-X76W-8C62-48MG
GHSA-XJ2C-G5XP-4P47

Affected Products

Craft Cms