Executive brief
Craft CMS, a popular content management system, contains a security flaw in its database migration component. This vulnerability allows an unauthenticated person to trigger system migration actions without permission. In practice, this could lead to unauthorized changes to the website's database structure or data loss, potentially disrupting the site's operations.
Technical details
A missing authorization vulnerability (CWE-862) exists in Craft CMS versions 5.9.5 and earlier within the 'migrate' endpoint. The root cause is located in 'src/controllers/AppController.php', where the 'migrate' action is explicitly included in the '$allowAnonymous' array, permitting access without authentication even when 'allowAdminChanges' is disabled. An unauthenticated remote attacker can send a POST request to '/actions/app/migrate' to trigger database migrations. This can lead to unauthorized database schema modifications or data integrity issues. Users should update to a version where this endpoint is properly protected.
Affected products
- Pixel & Tonic Craft CMS <= 5.9.5
Timeline
- 2026-05-27: disclosed: CVE published to NVD