top of page
perceptive_background_267k.jpg

Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).

Published:

26 mei 2026 om 22:00:00

Alert date:

27 mei 2026 om 21:06:41

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

Craft CMS version 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate). This security flaw allows unauthorized access to the migration functionality, potentially enabling attackers to execute unauthorized operations on the content management system. The vulnerability affects the application's migration endpoint which is typically used for database migrations and system updates. Proof-of-concept code has been made available on GitHub, increasing the risk of exploitation. Organizations using affected versions of Craft CMS should prioritize patching to prevent potential unauthorized access.

Technical details

Mitigation steps:

Affected products:

Craft CMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page