


Perceptive Security
SOC/SIEM Consultancy

Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).
Published:
26 May 2026 at 22:00:00
Alert date:
27 May 2026 at 20:13:41
Source:
nvd.nist.gov
Web Technologies
Craft CMS versions 5.9.5 and earlier contain a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate). This vulnerability allows unauthorized access to migration functionality which could potentially lead to system compromise. The vulnerability has been assigned CVE-2026-31266 and affects multiple versions of the popular content management system. Proof-of-concept code has been made available demonstrating the vulnerability. Organizations using affected versions should prioritize patching to prevent potential exploitation.
Technical details
Mitigation steps:
Affected products:
Craft CMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-31266
https://github.com/0xrixet/cms-security-poc
https://github.com/craftcms/cms
https://github.com/0xrixet/Craftcms-PoC-CVE-2026-31266
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
