


Perceptive Security
SOC/SIEM Consultancy

Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sour…
Published:
2 september 2026 om 00:00:00
Alert date:
2 september 2026 om 16:04:55
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Identity & Access
Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. The flaw allows an authenticated low-privilege author to bypass the replacePeerFiles permission check by omitting the assetId parameter from a request. When sourceAssetId and targetFilename are supplied without assetId, the target asset is resolved by folder and filename after permission checks have already executed, meaning the replacePeerFiles permission is never enforced. This enables an attacker with only the replaceFiles permission on a shared folder to overwrite a peer's asset file with attacker-controlled bytes. The vulnerability is an authorization logic flaw stemming from the order of operations in the permission enforcement flow. It requires authentication but only low-privilege access. The issue has been patched in Craft CMS version 5.10.11.
Technical details
Mitigation steps:
Affected products:
Craft CMS >= 5.0.0-RC1 and < 5.10.11
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-84800
https://github.com/craftcms/cms/security/advisories/GHSA-329j-cx85-8r56
https://www.vulncheck.com/advisories/craft-cms-5.0.0-rc1-before-5.10.11-file-overwrite-via-assets-replace-file
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
