CVE-2026-32267
From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their privileges to admin by abusing…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their privileges to admin by abusing UsersController->actionImpersonateWithToken. This issue has been patched in versions 4.17.6 and 5.9.12.
- CVSS 4.0
- 7.7 HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 7.73% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- craftcms/craft cms
- Source
- security-advisories@github.com
References
- https://github.com/craftcms/cms/commit/6301e217c5f15617d939c432cb770db50af14b33Patch
- https://github.com/craftcms/cms/security/advisories/GHSA-cc7p-2j3x-x7xfExploit, Patch, Vendor Advisory
- https://github.com/craftcms/cms/security/advisories/GHSA-cc7p-2j3x-x7xfExploit, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.