CVE-2026-33161

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can call assets/image-editor with the ID of a private asset they cannot view and still receive editor response data, including focalPoint. The endpoint returns private editing metadata without per-asset authorization validation. This issue has been patched in versions 4.17.8 and 5.9.14.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:-:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc3:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:5.0.0:-:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:5.0.0:rc1:*:*:*:*:*:*

History

26 Mar 2026, 17:09

Type Values Removed Values Added
References () https://github.com/craftcms/cms/commit/d30df3112220db1ffd6726a3ed11857014c7fb27 - () https://github.com/craftcms/cms/commit/d30df3112220db1ffd6726a3ed11857014c7fb27 - Patch
References () https://github.com/craftcms/cms/releases/tag/4.17.8 - () https://github.com/craftcms/cms/releases/tag/4.17.8 - Release Notes
References () https://github.com/craftcms/cms/releases/tag/5.9.14 - () https://github.com/craftcms/cms/releases/tag/5.9.14 - Release Notes
References () https://github.com/craftcms/cms/security/advisories/GHSA-vgjg-248p-rfm2 - () https://github.com/craftcms/cms/security/advisories/GHSA-vgjg-248p-rfm2 - Vendor Advisory
CPE cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:-:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:5.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc3:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:5.0.0:-:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc1:*:*:*:*:*:*
Summary
  • (es) Craft CMS es un sistema de gestión de contenido (CMS). Desde la versión 4.0.0-RC1 hasta antes de la versión 4.17.8 y desde la versión 5.0.0-RC1 hasta antes de la versión 5.9.14, un usuario autenticado con bajos privilegios puede llamar a assets/image-editor con el ID de un activo privado que no puede ver y aun así recibir datos de respuesta del editor, incluyendo focalPoint. El endpoint devuelve metadatos de edición privados sin validación de autorización por activo. Este problema ha sido parcheado en las versiones 4.17.8 y 5.9.14.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
First Time Craftcms
Craftcms craft Cms

24 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-24 18:16

Updated : 2026-03-26 17:09


NVD link : CVE-2026-33161

Mitre link : CVE-2026-33161

CVE.ORG link : CVE-2026-33161


JSON object : View

Products Affected

craftcms

  • craft_cms
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-862

Missing Authorization