CVE-2026-84802 Details
Description
Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit POST requests to the assets/move-info endpoint with arbitrary folderIds to retrieve asset count and total storage size for volumes they cannot access.
An information disclosure vulnerability has been identified in Craft CMS versions 5.7.0 prior to 5.10.12. The issue resides in the AssetsController's actionMoveInfo, which does not properly enforce volume permissions. This flaw allows authenticated control panel users to send POST requests to the assets/move-info endpoint with arbitrary folderIds. As a result, they can access asset counts and total storage sizes for volumes that are otherwise restricted.
Users can upgrade to Craft CMS version 5.10.12 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 2, 2026CISA-ADP
Assessed Sep 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/craftcms/cms/security/advisories/GHSA-5mjc-jqcw-6vrp | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/craftcms/cms/security/advisories/GHSA-5mjc-jqcw-6vrp | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/craft-cms-5.7.0-before-5.10.12-information-disclosure-via-assetscontroller | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Craft CMS | >= 5.7.0, < 5.10.12 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 2, 2026 | CVE Modified | CISA-ADP |
| Sep 2, 2026 | New CVE Received | [email protected] |
Volerion