Executive brief
Craft CMS is a content management system used by organizations to manage website content and media assets. A vulnerability in versions before 5.10.11 allows authenticated users to bypass permission checks and delete or replace other users' assets in shared volumes without authorization, potentially corrupting or removing important files and damaging content integrity.
Technical details
The vulnerability is an authorization bypass (CWE-862) in the assets/move-asset endpoint that fails to validate peer asset permissions when the force=1 parameter is supplied. An authenticated Control Panel user with asset management rights in a volume but lacking peer asset permissions can move their own asset into another user's folder with a conflicting filename; when force=1 is present, Craft merges and deletes the conflicting destination asset without checking if the attacker is authorized to modify or delete that asset. This affects Craft CMS versions 5.0.0-RC1 through 5.10.10, with a patch released in version 5.10.11. The attack requires network access and valid authentication but no user interaction.
Affected products
- Craft CMS 5.0.0-RC1 to 5.10.10
Timeline
- 2026-08-18: disclosed
- 2026-09-02: advisory
- 2026-09-02: patched: Craft CMS 5.10.11 released with fix