Intel

AIKIDO-2026-10550

craftcms/cms is vulnerable to Authorization Bypass

Authorization BypassGHSA-3w32-23wj-rxg3 Published Apr 24, 2026

75

High Risk

This Affects:

PHPcraftcms/cms
0.0.1 - 4.17.13
Fixed in 4.17.14
5.0.0 - 5.9.20
Fixed in 5.9.21
Are you affected? Scan for Free

TL;DR

Affected versions of craftcms/cms are vulnerable to Authorization Bypass due to incomplete permission checks. The update strengthens permission checks in the actionMoveFolder() and actionReplaceFile() method to prevent unauthorized asset folder moves.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

craftcms/cms is vulnerable to Authorization Bypass in versions 0.0.1 - 4.17.13 and 5.0.0 - 5.9.20.

How to fix this

Upgrade the craftcms/cms to a patch version.