Medium severity4.3NVD Advisory· Published Sep 2, 2026· Updated Sep 2, 2026
CVE-2026-84802
CVE-2026-84802
Description
Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit POST requests to the assets/move-info endpoint with arbitrary folderIds to retrieve asset count and total storage size for volumes they cannot access.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.