Description
Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw in the bulk-duplicate element action. An attacker who is only able to duplicate their own entires can submit an arbitrary id through the newAttributes request parameter. The duplication routine overrides its own id = null reset with that value and writes the attacker's attributes into the victim's existing entry row. ElementsController::beforeAction() pulls the request body into $this->_attributes and rejects requests that ship an id or canonicalId key at the top level, actionBulkDuplicate(), reads a separate newAttributes array and passes it straight through to the service layer. Elements::duplicateElement() clones the source element, sets id to null, and then hands the attacker's array to Craft::configure(), which overwrites the reset id with any numeric value inside $newAttributes. PHP Yii's saveElement() then performs an UPDATE against the row with that primary key instead of an INSERT. The attackers's title, slug, authorId, postDate, and UID land on the victim's entry. safeAttributes() on Entry includes id because the base element model exposes it, so the Collection::only() filter does not strip it. This issue has been fixed in version 5.9.21.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Craft CMS contains a mass-assignment flaw in its bulk‑duplicate element action. An authenticated user can submit an arbitrary numeric identifier through the newAttributes request parameter. The duplication routine, after resetting the new element’s id to null, replaces that value with the attacker’s supplied id, causing the system to update the row with that primary key instead of inserting a new entry. The attacker’s title, slug, authorId, postDate, and UID are therefore written into the victim’s entry model. Based on the description, it is inferred that the attacker may target any existing entry whose id they know, potentially compromising content integrity.

Affected Systems

The vulnerability affects Craft CMS versions 5.7.0 through 5.9.20 inclusive, for installations that expose the bulk‑duplicate element action to authenticated users. The issue was fixed in version 5.9.21 and later.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, while the EPSS score of < 1% reflects a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, which suggests no known active exploitation. The attack requires an authenticated user with access to the bulk‑duplicate feature, so exposure is limited to those roles; the impact is primarily to content integrity rather than system compromise.

Generated by OpenCVE AI on July 31, 2026 at 15:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Craft CMS to version 5.9.21 or later.
  • Restrict the bulk‑duplicate element action to trusted roles or disable it if not needed.
  • Monitor database write activity for unexpected updates indicating potential exploitation.

Generated by OpenCVE AI on July 31, 2026 at 15:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-x5m4-g2cq-52pq Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
History

Wed, 29 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Craftcms
Craftcms craftcms
Vendors & Products Craftcms
Craftcms craftcms

Thu, 02 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw in the bulk-duplicate element action. An attacker who is only able to duplicate their own entires can submit an arbitrary id through the newAttributes request parameter. The duplication routine overrides its own id = null reset with that value and writes the attacker's attributes into the victim's existing entry row. ElementsController::beforeAction() pulls the request body into $this->_attributes and rejects requests that ship an id or canonicalId key at the top level, actionBulkDuplicate(), reads a separate newAttributes array and passes it straight through to the service layer. Elements::duplicateElement() clones the source element, sets id to null, and then hands the attacker's array to Craft::configure(), which overwrites the reset id with any numeric value inside $newAttributes. PHP Yii's saveElement() then performs an UPDATE against the row with that primary key instead of an INSERT. The attackers's title, slug, authorId, postDate, and UID land on the victim's entry. safeAttributes() on Entry includes id because the base element model exposes it, so the Collection::only() filter does not strip it. This issue has been fixed in version 5.9.21.
Title Craft CMS: Mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
Weaknesses CWE-915
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Craftcms Craftcms
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-02T19:44:23.581Z

Reserved: 2026-06-04T16:26:05.985Z

Link: CVE-2026-50281

cve-icon Vulnrichment

Updated: 2026-07-02T19:44:18.395Z

cve-icon NVD

Status : Deferred

Published: 2026-07-02T17:17:00.000

Modified: 2026-07-02T20:17:03.500

Link: CVE-2026-50281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T15:15:02Z

Weaknesses
  • CWE-915

    Improperly Controlled Modification of Dynamically-Determined Object Attributes