PT-2026-94106 · Craft Cms · Craft Cms

CVE-2026-92589

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Craft CMS versions 5.0.0 through 5.10.12
Description A broken access control flaw exists in the 'actions/nested-elements/reorder' endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries permissions (but lacking savePeerEntries) opens another author's entry in read-only mode, the system grants a manageNestedElements::<ownerId>::field:<handle> authorization flag for Matrix or Address fields. The 'actions/nested-elements/reorder' endpoint relies solely on this session flag and fails to verify the caller's save permissions for the owner element. Consequently, a user with read-only access can send a POST request to the 'actions/nested-elements/reorder' endpoint using the ownerElementType, ownerId, ownerSiteId, attribute, elementIds, and offset parameters to modify the sort order of Matrix blocks or Addresses for content they are not permitted to edit.
Recommendations Update Craft CMS to version 5.10.13.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92589
GHSA-6FP2-8J9W-7MJ8

Affected Products

Craft Cms