top of page
perceptive_background_267k.jpg

Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads …

Published:

2 september 2026 om 00:00:00

Alert date:

2 september 2026 om 15:03:46

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

A critical authorization bypass vulnerability exists in Craft CMS versions >= 5.0.0-RC1 and < 5.10.11. The flaw resides in ElementsController::actionDeleteForSite(), which incorrectly checks deletion permissions against a user's provisional draft rather than the canonical element. This allows authenticated users with certain permissions (viewEntries, viewPeerEntries, saveEntries, savePeerEntries, editSite) but without the deleteEntriesForSite permission to hard-delete canonical entry site records. For single-site entries, this results in complete and irrecoverable deletion of the element and its content, bypassing Craft's recycle bin. The vulnerability stems from missing re-authorization after the provisional draft check propagates the deletion to the canonical element. Users should upgrade to Craft CMS 5.10.11 or later to remediate this issue.

Technical details

Mitigation steps:

Affected products:

Craft CMS >= 5.0.0-RC1 and < 5.10.11

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page