CVE Explorer
CVE-2026-28781
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the authorId attribute. A user with "Create Entries" permission can inject the authorIds[] (or authorId) parameter into the POST request, which the backend processes without verifying if the current user is authorized to assign authorship to others. Normally, this field is not present in the request for users without the necessary permissions. By manually
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-915","description":"CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3a7cff81643f53104e93c0dfb0b7391ec16b248f359fdab5d41adf0cc056d12b · sha256:e09375e13492bd27… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3a7cff81643f53104e93c0dfb0b7391ec16b248f359fdab5d41adf0cc056d12b · sha256:e09375e13492bd27… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"cms","vendor":"craftcms","versions":[{"status":"affected","version":">= 5.0.0-RC1, < 5.9.0-beta.1"},{"status":"affected","version":">= 4.0.0-RC1, < 4.17.0-beta.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:3a7cff81643f53104e93c0dfb0b7391ec16b248f359fdab5d41adf0cc056d12b · sha256:e09375e13492bd27… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:3a7cff81643f53104e93c0dfb0b7391ec16b248f359fdab5d41adf0cc056d12b · sha256:e09375e13492bd27… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-915","description":"CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3a7cff81643f53104e93c0dfb0b7391ec16b248f359fdab5d41adf0cc056d12b · sha256:e09375e13492bd27… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3a7cff81643f53104e93c0dfb0b7391ec16b248f359fdab5d41adf0cc056d12b · sha256:e09375e13492bd27… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/craftcms/cms/commit/830b403870cd784b47ae42a3f5a16e7ac2d7f5a8","tags":["x_refsource_MISC"],"url":"https://github.com/craftcms/cms/commit/830b403870cd784b47ae42a3f5a16e7ac2d7f5a8"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3a7cff81643f53104e93c0dfb0b7391ec16b248f359fdab5d41adf0cc056d12b · sha256:e09375e13492bd27… · /containers/cna/references/1
{"name":"https://github.com/craftcms/cms/commit/c6dcbdffaf6ab3ffe77d317336684d83699f4542","tags":["x_refsource_MISC"],"url":"https://github.com/craftcms/cms/commit/c6dcbdffaf6ab3ffe77d317336684d83699f4542"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3a7cff81643f53104e93c0dfb0b7391ec16b248f359fdab5d41adf0cc056d12b · sha256:e09375e13492bd27… · /containers/cna/references/2
{"name":"https://github.com/craftcms/cms/security/advisories/GHSA-2xfc-g69j-x2mp","tags":["x_refsource_CONFIRM"],"url":"https://github.com/craftcms/cms/security/advisories/GHSA-2xfc-g69j-x2mp"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3a7cff81643f53104e93c0dfb0b7391ec16b248f359fdab5d41adf0cc056d12b · sha256:e09375e13492bd27… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.