CVE Explorer
CVE-2026-50281
Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw in the bulk-duplicate element action. An attacker who is only able to duplicate their own entires can submit an arbitrary id through the newAttributes request parameter. The duplication routine overrides its own id = null reset with that value and writes the attacker's attributes into the victim's existing entry row. ElementsController::beforeAction() pulls the request body in
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"cms","vendor":"craftcms","versions":[{"status":"affected","version":">= 5.7.0, < 5.9.21"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:cf2541974caeb3e303f195dc343e6d91d4dcc515656ff98dad7997dc77b417dc · sha256:09f1ad1b2e5ba5a0… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:cf2541974caeb3e303f195dc343e6d91d4dcc515656ff98dad7997dc77b417dc · sha256:09f1ad1b2e5ba5a0… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-915","description":"CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cf2541974caeb3e303f195dc343e6d91d4dcc515656ff98dad7997dc77b417dc · sha256:09f1ad1b2e5ba5a0… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/craftcms/cms/commit/8f6587c25050bbb6e080d59c71f6bb8932fc8600","tags":["x_refsource_MISC"],"url":"https://github.com/craftcms/cms/commit/8f6587c25050bbb6e080d59c71f6bb8932fc8600"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cf2541974caeb3e303f195dc343e6d91d4dcc515656ff98dad7997dc77b417dc · sha256:09f1ad1b2e5ba5a0… · /containers/cna/references/1
{"name":"https://github.com/craftcms/cms/security/advisories/GHSA-x5m4-g2cq-52pq","tags":["x_refsource_CONFIRM"],"url":"https://github.com/craftcms/cms/security/advisories/GHSA-x5m4-g2cq-52pq"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cf2541974caeb3e303f195dc343e6d91d4dcc515656ff98dad7997dc77b417dc · sha256:09f1ad1b2e5ba5a0… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.