CVE-2026-84802: Craft CMS CMS

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit POST requests to the assets/move-info endpoint with arbitrary folderIds to retrieve asset count and total storage size for volumes they cannot access.

Affected products

  • Craft CMS CMS: from 5.7.0, before 5.10.12 (fixed in 5.10.12)

Published 2026-09-02. Last modified 2026-09-02.