{"id":"CVE-2026-50280","aliases":["GHSA-43cq-c2gq-pfpw"],"url":"https://o3.security/vulnerability/CVE-2026-50280","summary":"Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check","details":"Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 and above prior to 5.9.21, the EntriesController::actionMoveToSection() endpoint gates the destination section only by viewEntries:$section->uid rather than requiring saveEntries permission (the source entry is separately checked via Entry::canMove()). As a result, a low-privileged authenticated control-panel user who can move an entry out of its current section can call moveEntryToSection() to rewrite the entry's sectionId and save it into a section where they have read access but no write access. This breaks the section-level authorization model, letting a user with limited permissions inject content into a protected section and interfere with editorial boundaries, approval workflows, and section-specific business logic. This issue has been fixed in version 5.9.21.","published":"2026-07-01T23:43:49.095Z","modified":"2026-08-12T03:51:19.397664646Z","cvss":null,"epss":{"score":0.00404,"percentile":0.33764,"asOf":"2026-09-07"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"5.9.21"}],"fix":{"url":"https://github.com/craftcms/cms/commit/0a6b916f6367b0162b2eaf2366add67b45fa98ea","label":"craftcms/cms@0a6b916"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50280.json"},{"type":"ADVISORY","url":"https://github.com/craftcms/cms/security/advisories/GHSA-43cq-c2gq-pfpw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50280"},{"type":"FIX","url":"https://github.com/craftcms/cms/commit/0a6b916f6367b0162b2eaf2366add67b45fa98ea"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:19.397664646Z"}}