Junglewise Threat Intelligence

CVE-2026-50280: Craft CMS authorization bypass in EntriesController move-to-section

CVE-2026-50280 · Severity: medium · CVSS 4 · Published 2026-07-02

Technologies: Pixel & Tonic Craft CMS, craftcms/cms (Packagist). Vendors: Packagist.

Executive brief

Craft CMS, a popular content management system, contains a flaw that allows users with limited permissions to move content into restricted areas. An authenticated user who has permission to view a section but not edit it can bypass security checks to relocate entries into that protected section. This could allow unauthorized staff to interfere with editorial workflows, bypass approval processes, or modify content ownership in sensitive areas of the website.

Technical details

An authorization bypass exists in the `EntriesController::actionMoveToSection()` endpoint of Craft CMS. The root cause is an insufficient permission check: the controller verifies if a user has `viewEntries` permission for the destination section but fails to verify the required `saveEntries` permission. An attacker authenticated to the control panel can exploit this by sending a request to move an entry they already control into a destination section where they only have read access. This allows the attacker to relocate content into unauthorized sections, bypassing the intended section-level authorization model. The issue is fixed in version 5.9.21.

Affected products

  • Pixel & Tonic Craft CMS >= 5.0.0-RC1, < 5.9.21

Timeline

  • 2026-05-29: disclosed
  • 2026-07-02: advisory
  • 2026-07-02: patched: Fixed in version 5.9.21

References

Related threats