Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jxm3-pmm2-9gf6 | Craft CMS has Permission Bypass and IDOR in Duplicate Entry Action |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 04 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Mar 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, the "Duplicate" entry action does not properly verify if the user has permission to perform this action on the specific target elements. Even with only "View Entries" permission (where the "Duplicate" action is restricted in the UI), a user can bypass this restriction by sending a direct request. Furthermore, this vulnerability allows duplicating other users' entries by specifying their Entry IDs. Since Entry IDs are incremental, an attacker can trivially brute-force these IDs to duplicate and access restricted content across the system. This vulnerability is fixed in 5.9.0-beta.1 and 4.17.0-beta.1. | |
| Title | Craft has a Permission Bypass and IDOR in Duplicate Entry Action | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-04T17:35:08.922Z
Reserved: 2026-03-03T14:25:19.244Z
Link: CVE-2026-28782
Updated: 2026-03-04T17:35:03.476Z
Status : Awaiting Analysis
Published: 2026-03-04T17:16:21.533
Modified: 2026-03-04T18:08:05.730
Link: CVE-2026-28782
No data.
OpenCVE Enrichment
No data.
Github GHSA