{"id":"CVE-2026-33162","aliases":["GHSA-f582-6gf6-gx4g"],"url":"https://o3.security/vulnerability/CVE-2026-33162","summary":"Craft CMS: Authorization bypass in \"entries/move-to-section\" allows control panel user to move entries without section permissions","details":"Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/entries/move-to-section, even when they do not have saveEntries:{sectionUid} permission for either source or destination section. This issue has been patched in version 5.9.14.","published":"2026-03-24T17:32:27.208Z","modified":"2026-08-12T03:51:10.963255504Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"5.9.14"}],"fix":{"url":"https://github.com/craftcms/cms/commit/3c1ab1c4445dd9237855a66e6a06ecf3591a718e","label":"craftcms/cms@3c1ab1c"},"references":[{"type":"WEB","url":"https://github.com/craftcms/cms/releases/tag/5.9.14"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33162.json"},{"type":"ADVISORY","url":"https://github.com/craftcms/cms/security/advisories/GHSA-f582-6gf6-gx4g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33162"},{"type":"FIX","url":"https://github.com/craftcms/cms/commit/3c1ab1c4445dd9237855a66e6a06ecf3591a718e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:10.963255504Z"}}