PT-2026-55857 · Craft Cms · Craft Cms

·

CVE-2026-14794

·

Published

2026-07-06

·

Updated

2026-08-06

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions Craft CMS versions prior to 4.18.1
Description An improper authorization issue exists in the Charts Endpoint component within the actionGetNewUsersData() function of the src/controllers/ChartsController.php file. A remote attacker can exploit this by manipulating the userGroupId argument.
Recommendations Upgrade to version 4.18.1.

Exploit

Fix

Missing Authorization

Improper Authorization

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14794
GHSA-RMJ4-M9CP-MP9V
GHSA-RVMM-V933-JGXQ

Affected Products

Craft Cms