Executive brief
Craft CMS, a popular content management system, contains a security flaw where low-privileged users can view metadata and preview information for private files they are not authorized to access. By sending a specific request to the file preview system, an authenticated user can bypass permission checks to see private asset details. This could lead to the unauthorized disclosure of sensitive internal file information or metadata.
Technical details
An authorization bypass vulnerability exists in Craft CMS within the `assets/preview-file` endpoint. The application fails to enforce per-asset 'view' authorization checks before returning preview content (`previewHtml`). An authenticated attacker with low privileges can provide a maliciously controlled `assetId` to the endpoint to receive preview response data for private assets, even if their `canView` permission is set to false. This results in the exposure of private preview image routes and associated metadata (CWE-862, CWE-639). The issue is resolved in versions 4.17.8 and 5.9.14.
Affected products
- Pixel & Tonic Craft CMS >= 4.0.0-RC1, <= 4.17.7; >= 5.0.0-RC1, <= 5.9.13
Timeline
- 2026-03-24: disclosed
- 2026-03-26: advisory
- 2026-03-26: patched