Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check
Description
Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 and above prior to 5.9.21, the EntriesController::actionMoveToSection() endpoint gates the destination section only by viewEntries:$section->uid rather than requiring saveEntries permission (the source entry is separately checked via Entry::canMove()). As a result, a low-privileged authenticated control-panel user who can move an entry out of its current section can call moveEntryToSection() to rewrite the entry's sectionId and save it into a section where they have read access but no write access. This breaks the section-level authorization model, letting a user with limited permissions inject content into a protected section and interfere with editorial boundaries, approval workflows, and section-specific business logic. This issue has been fixed in version 5.9.21.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
craftcms/cmsPackagist | >= 5.0.0-RC1, < 5.9.21 | 5.9.21 |
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-43cq-c2gq-pfpwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-50280ghsaADVISORY
- github.com/craftcms/cms/commit/0a6b916f6367b0162b2eaf2366add67b45fa98eaghsax_refsource_MISCWEB
- github.com/craftcms/cms/security/advisories/GHSA-43cq-c2gq-pfpwghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.