CVE-2026-14794 Details
Description
A flaw has been found in Craft CMS up to 4.18.0.1. Affected by this vulnerability is the function actionGetNewUsersData of the file src/controllers/ChartsController.php of the component Charts Endpoint. This manipulation of the argument userGroupId causes improper authorization. The attack is possible to be carried out remotely. Upgrading to version 4.18.1 addresses this issue. Patch name: 9ee53efc1314e6aba32771c66a13e072a246f4ce. It is suggested to upgrade the affected component.
An authorization bypass vulnerability has been identified in Craft CMS versions prior to 4.18.0.1. The issue arises in the Charts Endpoint's actionGetNewUsersData function within src/controllers/ChartsController.php. The vulnerability allows improper authorization by manipulating the userGroupId parameter, enabling remote exploitation.
Users are advised to upgrade to Craft CMS version 4.18.1, which addresses this vulnerability. Instructions for upgrading can be found in the Craft CMS release notes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 6, 2026CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/craftcms/cms/commit/9ee53efc1314e6aba32771c66a13e072a246f4ce | [email protected] | Source CodeVendor |
| https://github.com/craftcms/cms/releases/tag/4.18.1 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-14794 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/850793 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/376388 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/376388/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Craft CMS | <= 4.18.0.1 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 6, 2026 | New CVE Received | [email protected] |
Volerion