CVE-2026-33162

Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/entries/move-to-section, even when they do not have saveEntries:{sectionUid} permission for either source or destination section. This issue has been patched in version 5.9.14.
Configurations

Configuration 1 (hide)

cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*

History

26 Mar 2026, 20:41

Type Values Removed Values Added
References () https://github.com/craftcms/cms/commit/3c1ab1c4445dd9237855a66e6a06ecf3591a718e - () https://github.com/craftcms/cms/commit/3c1ab1c4445dd9237855a66e6a06ecf3591a718e - Patch
References () https://github.com/craftcms/cms/releases/tag/5.9.14 - () https://github.com/craftcms/cms/releases/tag/5.9.14 - Release Notes
References () https://github.com/craftcms/cms/security/advisories/GHSA-f582-6gf6-gx4g - () https://github.com/craftcms/cms/security/advisories/GHSA-f582-6gf6-gx4g - Vendor Advisory
CPE cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
First Time Craftcms
Craftcms craft Cms
Summary
  • (es) Craft CMS es un sistema de gestión de contenido (CMS). Desde la versión 5.3.0 hasta antes de la versión 5.9.14, un usuario autenticado del panel de control con solo accessCp puede mover entradas entre secciones a través de POST /actions/entries/move-to-section, incluso cuando no tienen el permiso saveEntries:{sectionUid} para la sección de origen o de destino. Este problema ha sido parcheado en la versión 5.9.14.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

24 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-24 18:16

Updated : 2026-03-26 20:41


NVD link : CVE-2026-33162

Mitre link : CVE-2026-33162

CVE.ORG link : CVE-2026-33162


JSON object : View

Products Affected

craftcms

  • craft_cms
CWE
CWE-285

Improper Authorization

CWE-862

Missing Authorization