CVE-2026-28781
Last modified
CVE-2026-28781 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the authorId attribute. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the authorId attribute. A user with "Create Entries" permission can inject the authorIds[] (or authorId) parameter into the POST request, which the backend processes without verifying if the current user is authorized to assign authorship to others. Normally, this field is not present in the request for users without the necessary permissions. By manually adding this parameter, an attacker can attribute the new entry to any user, including Admins. This effectively "spoofs" the authorship. This vulnerability is fixed in 4.17.0-beta.1 and 5.9.0-beta.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Craftcms | Craft Cms | > 4.0.0, < 4.17.0 |
| Craftcms | Craft Cms | > 5.0.0, < 5.9.0 |
| Craftcms | Craft Cms | 4.0.0 |
| Craftcms | Craft Cms | 5.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-28781?
How severe is CVE-2026-28781?
How do I fix CVE-2026-28781?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-28776International Datacasting Corporation (IDC) SFX Series Super…9.8
- CVE-2026-28777International Datacasting Corporation (IDC) SFX2100 Satell…9.8
- CVE-2026-28778International Datacasting Corporation (IDC) SFX Series Super…9.8
- CVE-2026-28779Apache Airflow versions 3.1.0 through 3.1.7 session token (_…7.5
- CVE-2026-2878In Progress® Telerik® UI for AJAX, versions prior to 2026.1.…5.9
- CVE-2026-28780Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of…9.8
- CVE-2026-28782Craft is a content management system (CMS). Prior to 5.9.0-b…4.3
- CVE-2026-28783Craft is a content management system (CMS). Prior to 5.9.0-b…9.1
- CVE-2026-28784Craft is a content management system (CMS). Prior to 5.8.22 …7.2
- CVE-2026-28785Ghostfolio is an open source wealth management software. Pri…9.8
- CVE-2026-28786Open WebUI is a self-hosted artificial intelligence platform…4.3
- CVE-2026-28787OneUptime is a solution for monitoring and managing online s…9
Are you affected by CVE-2026-28781?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
