


Perceptive Security
SOC/SIEM Consultancy

Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 21:06:41
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
Craft CMS version 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate). This security flaw allows unauthorized access to the migration functionality, potentially enabling attackers to execute unauthorized operations on the content management system. The vulnerability affects the application's migration endpoint which is typically used for database migrations and system updates. Proof-of-concept code has been made available on GitHub, increasing the risk of exploitation. Organizations using affected versions of Craft CMS should prioritize patching to prevent potential unauthorized access.
Technical details
Mitigation steps:
Affected products:
Craft CMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-31266
https://github.com/0xrixet/cms-security-poc
https://github.com/craftcms/cms
https://github.com/0xrixet/Craftcms-PoC-CVE-2026-31266
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
