Vulnerability Description
Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/entries/move-to-section, even when they do not have saveEntries:{sectionUid} permission for either source or destination section. This issue has been patched in version 5.9.14.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Craftcms | Craft Cms | >= 5.3.0, < 5.9.14 |
Related Weaknesses (CWE)
References
- https://github.com/craftcms/cms/commit/3c1ab1c4445dd9237855a66e6a06ecf3591a718ePatch
- https://github.com/craftcms/cms/releases/tag/5.9.14Release Notes
- https://github.com/craftcms/cms/security/advisories/GHSA-f582-6gf6-gx4gVendor Advisory
FAQ
What is CVE-2026-33162?
CVE-2026-33162 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/e...
How severe is CVE-2026-33162?
CVE-2026-33162 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-33162?
Check the references section above for vendor advisories and patch information. Affected products include: Craftcms Craft Cms.