CVE-2026-50282: Craft CMS: Unauthorized Deletion of Destination Folders During Forced Moves

Published Jul 2, 2026
·
Updated

Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above prior to 4.17.14 contain an authorization issue where a forced folder move can delete a conflicting destination folder without destination delete permission. Function craft\\controllers\\AssetsController::actionMoveFolder() supports moving an asset folder into a destination parent folder. If a folder with the same name already exists at the destination, the action can be called with force=true to overwrite the destination. This issue has been resolved in versions 5.9.21 and 4.17.14.

Other sources

We have identified an authorization issue in Craft CMS where a forced folder move can delete a conflicting destination folder without destination delete permission.

Description

Craft CMS’s craft\\controllers\\AssetsController::actionMoveFolder() supports moving an asset folder into a destination parent folder. If a folder with the same name already exists at the destination, the action can be called with force=true to overwrite the destination.

The permission checks for this action allow:

- deleteAssets:<sourceVolumeUid> for the folder being moved - createFolders:<destVolumeUid> for the destination parent folder - saveAssets:<destVolumeUid> for the destination parent folder

The action does not require deleteAssets on the destination volume or destination conflict folder. When force=true and a name conflict exists, the code deletes the destination folder to resolve the conflict.

php $this->requireVolumePermissionByFolder('deleteAssets', $folderToMove); $this->requireVolumePermissionByFolder('createFolders', $destinationFolder); $this->requireVolumePermissionByFolder('saveAssets', $destinationFolder);

src/controllers/AssetsController.php:L751-L753

Indexed destination conflicts are deleted via the Assets service:

php $assets->deleteFoldersByIds($existingFolder->id);

src/controllers/AssetsController.php:L798-L798

Unindexed destination conflicts are deleted directly in the volume filesystem:

php $targetVolume->deleteDirectory(rtrim($destinationFolder->path, '/') . '/' . $folderToMove->name);

src/controllers/AssetsController.php:L815

Impact

A user who cannot delete assets in a destination volume can still delete a destination folder and its contents by triggering a forced move into a conflicting name. This can cause asset loss, broken references in entries and fields that point to deleted assets, and operational disruption.

GitHub

Affected Software

4 affected componentsFixes available
Craft CMS Craft CMS>=5.0.0-RC1<5.9.21
Craft CMS Craft CMS>=4.0.0-RC1<4.17.14
composer/craftcms/cms>=4.0.0-RC1<4.17.14
4.17.14
composer/craftcms/cms>=5.0.0-RC1<5.9.21
5.9.21

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/craftcms/cms to a version that resolves this vulnerability.

    Fixed in 4.17.14
  2. Upgrade

    Upgrade composer/craftcms/cms to a version that resolves this vulnerability.

    Fixed in 5.9.21
  3. Upgrade

    Upgrade Craft CMS to a version that resolves this vulnerability.

    Fixed in 5.9.21
  4. Upgrade

    Upgrade Craft CMS to a version that resolves this vulnerability.

    Fixed in 4.17.14

Event History

Jul 2, 2026
CVE Published
via MITRE·04:15 PM
Data Sourced
via MITRE·04:15 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·08:03 PM
Data Sourced
via GitHub·08:03 PM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-50282?

CVE-2026-50282 has a risk score of 37, indicating a medium severity vulnerability.

2

How do I fix CVE-2026-50282?

To remediate CVE-2026-50282, upgrade Craft CMS to version 5.9.21 or 4.17.14 or later.

3

What versions are affected by CVE-2026-50282?

CVE-2026-50282 affects Craft CMS versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above, prior to 4.17.14.

4

What type of issue is addressed by CVE-2026-50282?

CVE-2026-50282 addresses an authorization issue that allows unauthorized deletion of destination folders during forced moves.

5

Who is affected by CVE-2026-50282?

Users of Craft CMS versions listed in the vulnerability report who are utilizing folder move functionalities are at risk from CVE-2026-50282.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203