CVE-2026-33159

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, guest users can access Config Sync updater index, obtain signed data, and execute state-changing Config Sync actions (regenerate-yaml, apply-yaml-changes) without authentication. This issue has been patched in versions 4.17.8 and 5.9.14.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:-:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc3:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:5.0.0:-:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:5.0.0:rc1:*:*:*:*:*:*

History

26 Mar 2026, 17:08

Type Values Removed Values Added
CPE cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:-:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:5.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc3:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:5.0.0:-:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc1:*:*:*:*:*:*
Summary
  • (es) Craft CMS es un sistema de gestión de contenido (CMS). Desde la versión 4.0.0-RC1 hasta antes de la versión 4.17.8 y desde la versión 5.0.0-RC1 hasta antes de la versión 5.9.14, los usuarios invitados pueden acceder al índice del actualizador de Config Sync, obtener datos firmados y ejecutar acciones de Config Sync que cambian el estado (regenerate-yaml, apply-yaml-changes) sin autenticación. Este problema ha sido parcheado en las versiones 4.17.8 y 5.9.14.
References () https://github.com/craftcms/cms/commit/7f0ead833f7c2b91ae12003caad833479dd08592 - () https://github.com/craftcms/cms/commit/7f0ead833f7c2b91ae12003caad833479dd08592 - Patch
References () https://github.com/craftcms/cms/releases/tag/4.17.8 - () https://github.com/craftcms/cms/releases/tag/4.17.8 - Release Notes
References () https://github.com/craftcms/cms/releases/tag/5.9.14 - () https://github.com/craftcms/cms/releases/tag/5.9.14 - Release Notes
References () https://github.com/craftcms/cms/security/advisories/GHSA-6mrr-q3pj-h53w - () https://github.com/craftcms/cms/security/advisories/GHSA-6mrr-q3pj-h53w - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Craftcms
Craftcms craft Cms

24 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-24 18:16

Updated : 2026-03-26 17:08


NVD link : CVE-2026-33159

Mitre link : CVE-2026-33159

CVE.ORG link : CVE-2026-33159


JSON object : View

Products Affected

craftcms

  • craft_cms
CWE
CWE-306

Missing Authentication for Critical Function

CWE-862

Missing Authorization