Description
Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw in the bulk-duplicate element action. An attacker who is only able to duplicate their own entires can submit an arbitrary id through the newAttributes request parameter. The duplication routine overrides its own id = null reset with that value and writes the attacker's attributes into the victim's existing entry row. ElementsController::beforeAction() pulls the request body into $this->_attributes and rejects requests that ship an id or canonicalId key at the top level, actionBulkDuplicate(), reads a separate newAttributes array and passes it straight through to the service layer. Elements::duplicateElement() clones the source element, sets id to null, and then hands the attacker's array to Craft::configure(), which overwrites the reset id with any numeric value inside $newAttributes. PHP Yii's saveElement() then performs an UPDATE against the row with that primary key instead of an INSERT. The attackers's title, slug, authorId, postDate, and UID land on the victim's entry. safeAttributes() on Entry includes id because the base element model exposes it, so the Collection::only() filter does not strip it. This issue has been fixed in version 5.9.21.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a mass‑assignment flaw in Craft CMS’s bulk‑duplicate element action that allows an authenticated attacker to supply an arbitrary numeric id via the newAttributes request parameter. The duplication routine resets its own id to null but then merges the attacker’s array, overwriting the id in the configuration step and causing the system to perform an UPDATE against the existing entry instead of an INSERT. This results in the attacker’s title, slug, authorId, postDate, the victim’s entry row, thereby compromising content integrity.

Affected Systems

The flaw impacts Craft CMS versions .7.0 and above, up to but not including 5.9.21, for installations that expose the bulk‑duplicate element action to authenticated users. It has been fixed in version 5.9.21 and later.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, while the EPSS score of < 1% reflects a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploitation. The attack requires an authenticated user who can access the bulk‑duplicate action on their own entries; the flaw then allows that user to overwrite arbitrary existing entries by supplying a target id, potentially subverting content integrity.

Generated by OpenCVE AI on July 21, 2026 at 11:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Craft CMS to version 5.9.21 or later.
  • Restrict the bulk‑duplicate element action to trusted roles or disable it if not required.
  • Review database updates that may indicate exploitation of the mass‑assignment flaw.

Generated by OpenCVE AI on July 21, 2026 at 11:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-x5m4-g2cq-52pq Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
History

Thu, 02 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw in the bulk-duplicate element action. An attacker who is only able to duplicate their own entires can submit an arbitrary id through the newAttributes request parameter. The duplication routine overrides its own id = null reset with that value and writes the attacker's attributes into the victim's existing entry row. ElementsController::beforeAction() pulls the request body into $this->_attributes and rejects requests that ship an id or canonicalId key at the top level, actionBulkDuplicate(), reads a separate newAttributes array and passes it straight through to the service layer. Elements::duplicateElement() clones the source element, sets id to null, and then hands the attacker's array to Craft::configure(), which overwrites the reset id with any numeric value inside $newAttributes. PHP Yii's saveElement() then performs an UPDATE against the row with that primary key instead of an INSERT. The attackers's title, slug, authorId, postDate, and UID land on the victim's entry. safeAttributes() on Entry includes id because the base element model exposes it, so the Collection::only() filter does not strip it. This issue has been fixed in version 5.9.21.
Title Craft CMS: Mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
Weaknesses CWE-915
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-02T19:44:23.581Z

Reserved: 2026-06-04T16:26:05.985Z

Link: CVE-2026-50281

cve-icon Vulnrichment

Updated: 2026-07-02T19:44:18.395Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:15:05Z

Weaknesses
  • CWE-915

    Improperly Controlled Modification of Dynamically-Determined Object Attributes