CVE-2026-56385: Craft CMS CMS
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-file endpoint. The action does not enforce per-asset view authorization before returning preview content, allowing an authenticated low-privileged user to supply a controlled assetId for an asset they are not permitted to view and still receive preview response data (previewHtml), including a private preview image route containing the target private assetId. Fixed in 5.9.14 and 4.17.8.
Affected products
- Craft CMS CMS: from 5.0.0-RC1, before 5.9.14 (fixed in 5.9.14); from 4.0.0-RC1, before 4.17.8 (fixed in 4.17.8)
Published 2026-06-21. Last modified 2026-06-22.