CVE-2026-32267 Details
Description
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their privileges to admin by abusing UsersController->actionImpersonateWithToken. This issue has been patched in versions 4.17.6 and 5.9.12.
A privilege escalation vulnerability has been identified in Craft CMS versions 4.0.0-RC1 prior to 4.17.6 and 5.0.0-RC1 prior to 5.9.12. The issue allows low-privilege users, or unauthenticated users with a shared URL, to gain admin rights by exploiting the UsersController's actionImpersonateWithToken. The vulnerability arises because the impersonation action does not properly validate tokens, allowing unauthorized access to admin privileges.
Users should update Craft CMS to version 4.17.6 or 5.9.12.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/craftcms/cms/security/advisories/GHSA-cc7p-2j3x-x7xf | CISA-ADP | ExploitPatchVendor Advisory |
| https://github.com/craftcms/cms/commit/6301e217c5f15617d939c432cb770db50af14b33 | [email protected] | Patch |
| https://github.com/craftcms/cms/security/advisories/GHSA-cc7p-2j3x-x7xf | [email protected] | ExploitPatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| craftcms craft cms | >= 4.0.0.1, < 4.17.6 >= 5.0.1, < 5.9.12 4.0.0 - 4.0.0 rc1 4.0.0 rc2 4.0.0 rc3 5.0.0 - 5.0.0 rc1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2026 | Initial Analysis | [email protected] |
| Mar 17, 2026 | CVE Modified | [email protected] |
| Mar 17, 2026 | CVE Modified | CISA-ADP |
| Mar 16, 2026 | New CVE Received | [email protected] |