CVE-2026-56385 Details
Description
Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-file endpoint. The action does not enforce per-asset view authorization before returning preview content, allowing an authenticated low-privileged user to supply a controlled assetId for an asset they are not permitted to view and still receive preview response data (previewHtml), including a private preview image route containing the target private assetId. Fixed in 5.9.14 and 4.17.8.
An authorization bypass vulnerability has been identified in Craft CMS versions 5.0.0-RC1 prior to 5.9.14 and 4.0.0-RC1 prior to 4.17.8. The vulnerability exists in the assets/preview-file endpoint, where the action fails to enforce per-asset view authorization before delivering preview content. This oversight allows an authenticated low-privileged user to manipulate the assetId parameter to access preview data for assets they are not authorized to view. The response includes previewHtml containing a private image route with the targeted assetId, despite the user lacking permission to view it.
Users can upgrade to Craft CMS versions 5.9.14 or 4.17.8 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 21, 2026CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Craft CMS | >= 5.0.0-RC1, <= 5.9.13 (semver) >= 4.0.0-RC1, <= 4.17.7 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 21, 2026 | New CVE Received | [email protected] |
Volerion