Junglewise Threat Intelligence

CVE-2026-14793: Craft CMS authorization bypass in GlobalsController reorder-sets

CVE-2026-14793 · Severity: medium · CVSS 4.3 · Published 2026-07-06

Technologies: Craft CMS. Vendors: Craft CMS.

Executive brief

Craft CMS, a popular content management system, contains a flaw where certain administrative settings can be modified by users who do not have administrator privileges. Specifically, any user with access to the control panel can change the display order of 'Global Sets,' which are site-wide content containers. While this does not allow for the theft or deletion of data, it can disrupt site operations by causing configuration conflicts and cluttering version control history.

Technical details

The `reorder-sets` action within the `GlobalsController` in Craft CMS fails to implement the `requireAdmin()` authorization check. An authenticated attacker with access to the control panel can send a crafted POST request to the `/actions/globals/reorder-sets` endpoint to permanently reorder global sets in the project configuration. This vulnerability stems from an inconsistent application of security gates compared to adjacent administrative functions like `save-set` and `delete-set`. The impact is limited to integrity, as it allows unauthorized modification of the project config file, which can lead to merge conflicts in version-controlled environments. The issue is resolved in versions 4.18.1 and 5.10.3.

Affected products

  • Craft CMS Craft CMS >= 4.0.0-RC1, < 4.18.1; >= 5.0.0-RC1, < 5.10.3

Timeline

  • 2026-07-25: disclosed
  • 2026-08-06: advisory: GitHub Advisory published
  • 2026-05-22: patched: Release of version 4.18.1

References