Junglewise Threat Intelligence

CVE-2026-72785: Craft CMS authorization bypass in category structure editing

CVE-2026-72785 · Severity: medium · CVSS 4.3 · Published 2026-08-11

Technologies: craftcms/cms (Packagist). Vendors: Craft CMS, Packagist.

Executive brief

Craft CMS is a content management system used to organize and manage website content, including structured category hierarchies. A vulnerability allows users with only read-only access to categories to permanently modify the category structure by reordering and re-parenting categories, which changes category URLs and can break website navigation menus built from the category taxonomy.

Technical details

This is an authorization bypass vulnerability (CWE-863) in Craft CMS versions 5.0.0-RC1 through 5.10.5. The root cause is that the structureEditable flag is computed from the viewCategories permission rather than the saveCategories permission; when a read-only category index renders, the system calls authorize('editStructure:<structureId>') at read time, and StructuresController then trusts this session grant for the structures/move-element mutation without re-checking write permissions. An authenticated user holding only viewCategories permission can invoke structures/move-element to reorder and re-parent categories. Because category URIs are derived from their position in the structure, moving categories changes their URLs and those of descendants, corrupting navigation built from the taxonomy. The vulnerability is fixed in version 5.10.6.

Affected products

  • Craft CMS CMS 5.0.0-RC1 through 5.10.5

Timeline

  • 2026-07-25: disclosed: GitHub Security Advisory GHSA-xxpx-f366-4xpq published
  • 2026-08-11: advisory: CVE-2026-72785 published
  • 2026-08-11: patched: Fix released in version 5.10.6

References

Related threats