Intel

AIKIDO-2026-933735

craftcms/ckeditor is vulnerable to Broken Access Control

Broken Access ControlGHSA-jcjm-q9x2-72xv Published Today

71

High Risk

This Affects:

PHPcraftcms/ckeditor
4.0.0 - 5.6.1
Fixed in 5.7.0
Are you affected? Scan for Free

TL;DR

CkeditorController::actionDuplicateNestedEntry() duplicates a nested entry identified by user-supplied entryId and targetOwnerId parameters without verifying that the requesting user can view the source entry or save the target owner element. A control panel user can duplicate nested entries into owners they have no save permission for, and view entry content they have no view permission for, by supplying element IDs alone. The fix requires the looked-up element to be a nested element and checks source view and target save permissions before duplicating.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use nested entries within CKEditor fields.

Background info

craftcms/ckeditor is vulnerable to Broken Access Control in versions 4.0.0 - 5.6.1.

How to fix this

Upgrade the craftcms/ckeditor library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform