Executive brief
Craft CMS, a popular content management system, contains a vulnerability that allows low-privileged users to change the assigned author of an entry without proper permission. By exploiting a gap in how the system checks permissions during the entry saving process, an authenticated user can reassign content to other users. This can lead to falsified audit trails, unauthorized reassignment of responsibility, and disruption of approval workflows.
Technical details
An improper authorization vulnerability exists in `EntriesController::actionSaveEntry()` due to a 'check-then-act' race-like logic gap. The controller enforces edit permissions on the original entry state before calling `_populateEntryModel()`, which processes attacker-supplied `authors` or `author` parameters. The `canChangeAuthor()` check is evaluated against the old authorship state; if the current user is an existing author, the change is permitted. Because the controller fails to re-verify authorization after the author list is mutated but before the element is saved, a user can reassign authorship to any other user without the `changeAuthorForPeerEntries` permission. This is fixed in version 5.9.21.
Affected products
- Pixel & Tonic Craft CMS >= 5.0.0-RC1, < 5.9.21
Timeline
- 2026-05-29: disclosed
- 2026-07-02: advisory
- 2026-07-02: patched: Fixed in version 5.9.21