Description
Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit POST requests to the assets/move-info endpoint with arbitrary folderIds to retrieve asset count and total storage size for volumes they cannot access.
Published: 2026-09-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in Craft CMS versions 5.7.0 through 5.10.11, where the AssetsController::actionMoveInfo endpoint does not enforce volume permission checks. Authenticated control panel users can send a POST request to /assets/move-info with arbitrary folder identifiers and obtain the asset count and total storage size for volumes they lack access to, leaking information about content usage and storage distribution.

Affected Systems

The affected product is Craft CMS, and the vulnerability applies to all releases from version 5.7.0 up to, but not including, 5.10.12. Administrators or users with control panel access are the relevant staff who could exploit this flaw.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate risk. Because EPSS is not available, the likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalogue. Exploitation requires authenticated control‑panel privileges, and the attacker gains only data disclosure rather than code execution or privilege escalation. Nonetheless, any user with access to the control panel who can submit arbitrary POST requests to the endpoint could abuse the flaw.

Generated by OpenCVE AI on September 2, 2026 at 12:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Craft CMS to version 5.10.12 or newer, which includes the fix that enforces proper volume permission checks in AssetsController::actionMoveInfo.
  • If an immediate upgrade is not feasible, temporarily restrict the assets/move-info endpoint to users with explicit permission to view volume statistics or remove the endpoint from the application altogether.
  • Ensure that all control panel users have the minimum necessary permissions and review volume permission configurations so that non‑privileged users cannot invoke the vulnerable endpoint.

Generated by OpenCVE AI on September 2, 2026 at 12:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit POST requests to the assets/move-info endpoint with arbitrary folderIds to retrieve asset count and total storage size for volumes they cannot access.
Title Craft CMS 5.7.0 before 5.10.12 Information Disclosure via AssetsController
First Time appeared Craftcms
Craftcms craft Cms
Weaknesses CWE-862
CPEs cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Vendors & Products Craftcms
Craftcms craft Cms
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Craftcms Craft Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-02T12:40:15.581Z

Reserved: 2026-09-02T10:19:32.991Z

Link: CVE-2026-84802

cve-icon Vulnrichment

Updated: 2026-09-02T12:40:11.264Z

cve-icon NVD

Status : Deferred

Published: 2026-09-02T12:17:17.050

Modified: 2026-09-02T13:54:48.797

Link: CVE-2026-84802

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T13:00:13Z

Weaknesses