Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement. | |
| Title | Craft CMS 5.0.0 through 5.10.10 Authorization Bypass via assets/move-asset | |
| First Time appeared |
Craftcms
Craftcms craft Cms |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Craftcms
Craftcms craft Cms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T02:25:35.585Z
Reserved: 2026-09-02T10:19:06.330Z
Link: CVE-2026-84794
Updated: 2026-09-04T02:25:31.867Z
Status : Deferred
Published: 2026-09-02T12:17:15.957
Modified: 2026-09-04T03:17:45.240
Link: CVE-2026-84794
No data.
OpenCVE Enrichment
Updated: 2026-09-02T13:00:13Z