PT-2026-94106 · Craft Cms · Craft Cms
CVE-2026-92589
·
Published
2026-09-16
·
Updated
2026-09-16
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Craft CMS versions 5.0.0 through 5.10.12
Description
A broken access control flaw exists in the 'actions/nested-elements/reorder' endpoint. When an authenticated control panel user with
viewEntries and viewPeerEntries permissions (but lacking savePeerEntries) opens another author's entry in read-only mode, the system grants a manageNestedElements::<ownerId>::field:<handle> authorization flag for Matrix or Address fields. The 'actions/nested-elements/reorder' endpoint relies solely on this session flag and fails to verify the caller's save permissions for the owner element. Consequently, a user with read-only access can send a POST request to the 'actions/nested-elements/reorder' endpoint using the ownerElementType, ownerId, ownerSiteId, attribute, elementIds, and offset parameters to modify the sort order of Matrix blocks or Addresses for content they are not permitted to edit.Recommendations
Update Craft CMS to version 5.10.13.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Craft Cms