CVE-2026-31266: High severity Pixel & Tonic Craft CMS vulnerability
Published May 27, 2026
·Updated
Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).
Affected Software
1 affected component
Pixel & Tonic Craft CMS<=5.9.5
Event History
May 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-31266?
CVE-2026-31266 has a high severity rating of 7.3.
2
What type of vulnerability is CVE-2026-31266?
CVE-2026-31266 is a Missing Authorization vulnerability affecting the migrate endpoint.
3
How do I fix CVE-2026-31266?
To fix CVE-2026-31266, upgrade to Craft CMS version 5.9.6 or later.
4
What software is affected by CVE-2026-31266?
CVE-2026-31266 affects Pixel & Tonic Craft CMS versions 5.9.5 and earlier.
5
Is CVE-2026-31266 exploitable remotely?
Yes, CVE-2026-31266 is exploitable remotely due to its nature as a Missing Authorization vulnerability.