Description
Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) opens another author's entry in read-only mode, Craft unconditionally grants that session a `manageNestedElements::<ownerId>::field:<handle>` authorization flag for the entry's Matrix/Address fields. Unlike the corresponding delete endpoint, actions/nested-elements/reorder trusts this session flag alone and never rechecks the caller's save permission for the owner element. As a result, a view-only user can POST to actions/nested-elements/reorder using the ownerElementType, ownerId, ownerSiteId, attribute, elementIds, and offset parameters present in the read-only page source and rewrite the sort order of Matrix blocks or Addresses belonging to content they are explicitly denied save access to.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of nested elements and potential privilege escalation
Action: Patch promptly
AI Analysis

Impact

The flaw occurs when an authenticated control panel user who can view entries but cannot save them opens another author's entry in read‑only mode. During that session Craft CMS grants a manageNestedElements flag for the entry’s Matrix or Address fields, and the reorder endpoint relies solely on that flag without checking whether the caller holds save permission for the owning element. Consequently, the attacker can send a POST request to actions/nested-elements/reorder, supplying the parameters visible in the page source, and re‑order the target item blocks without having direct edit rights. This results in unauthorized alteration of content ordering, which can misrepresent information or undermine trust in the site’s data.

Affected Systems

Craft CMS versions 5.0.0 through 5.10.12 from the vendor Craft CMS are affected. The flaw is fixed in version 5.10.13 and later.

Risk and Exploitability

The vulnerability scores a moderate 5.3 on CVSS, and its EPSS score is under 1%, indicating a very low likelihood of exploitation in the wild. It is not listed in CISA’s KEV catalog. The attack requires an authenticated user with view permission but lacking save permission, so the risk is contained to sites that grant such limited access. Nevertheless, the possibility of unauthorized content manipulation warrants prompt remediation, especially on high‑profile or publicly‑facing installations.

Generated by OpenCVE AI on September 18, 2026 at 05:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Craft CMS 5.10.13 or later to deploy the vendor‑issued fix.
  • Review control‑panel user roles and remove the viewPeerEntries permission from users that should not rearrange nested elements.
  • If an immediate upgrade is not feasible, restrict or block POST requests to actions/nested-elements/reorder for users without savePeerEntries via web‑server rules or custom middleware.

Generated by OpenCVE AI on September 18, 2026 at 05:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) opens another author's entry in read-only mode, Craft unconditionally grants that session a `manageNestedElements::<ownerId>::field:<handle>` authorization flag for the entry's Matrix/Address fields. Unlike the corresponding delete endpoint, actions/nested-elements/reorder trusts this session flag alone and never rechecks the caller's save permission for the owner element. As a result, a view-only user can POST to actions/nested-elements/reorder using the ownerElementType, ownerId, ownerSiteId, attribute, elementIds, and offset parameters present in the read-only page source and rewrite the sort order of Matrix blocks or Addresses belonging to content they are explicitly denied save access to.
Title Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder
First Time appeared Craftcms
Craftcms craft Cms
Weaknesses CWE-862
CPEs cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Vendors & Products Craftcms
Craftcms craft Cms
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Craftcms Craft Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T20:12:02.490Z

Reserved: 2026-09-16T13:47:49.170Z

Link: CVE-2026-92589

cve-icon Vulnrichment

Updated: 2026-09-18T20:11:58.085Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T22:18:29.583

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-92589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:00:06Z

Weaknesses