Junglewise Threat Intelligence

CVE-2026-31266: Pixel & Tonic Craft CMS missing authorization in migrate endpoint

CVE-2026-31266 · Severity: info · CVSS 6.5 · Published 2026-05-27

Technologies: Pixel & Tonic Craft CMS.

Executive brief

Craft CMS, a popular content management system, contains a security flaw in its database migration component. This vulnerability allows an unauthenticated person to trigger system migration actions without permission. In practice, this could lead to unauthorized changes to the website's database structure or data loss, potentially disrupting the site's operations.

Technical details

A missing authorization vulnerability (CWE-862) exists in Craft CMS versions 5.9.5 and earlier within the 'migrate' endpoint. The root cause is located in 'src/controllers/AppController.php', where the 'migrate' action is explicitly included in the '$allowAnonymous' array, permitting access without authentication even when 'allowAdminChanges' is disabled. An unauthenticated remote attacker can send a POST request to '/actions/app/migrate' to trigger database migrations. This can lead to unauthorized database schema modifications or data integrity issues. Users should update to a version where this endpoint is properly protected.

Affected products

  • Pixel & Tonic Craft CMS <= 5.9.5

Timeline

  • 2026-05-27: disclosed: CVE published to NVD

References