CVE-2026-50282: Craft CMS: Unauthorized Deletion of Destination Folders During Forced Moves
Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above prior to 4.17.14 contain an authorization issue where a forced folder move can delete a conflicting destination folder without destination delete permission. Function craft\\controllers\\AssetsController::actionMoveFolder() supports moving an asset folder into a destination parent folder. If a folder with the same name already exists at the destination, the action can be called with force=true to overwrite the destination. This issue has been resolved in versions 5.9.21 and 4.17.14.
Other sources
We have identified an authorization issue in Craft CMS where a forced folder move can delete a conflicting destination folder without destination delete permission.
Description
Craft CMS’s craft\\controllers\\AssetsController::actionMoveFolder() supports moving an asset folder into a destination parent folder. If a folder with the same name already exists at the destination, the action can be called with force=true to overwrite the destination.
The permission checks for this action allow:
- deleteAssets:<sourceVolumeUid> for the folder being moved - createFolders:<destVolumeUid> for the destination parent folder - saveAssets:<destVolumeUid> for the destination parent folder
The action does not require deleteAssets on the destination volume or destination conflict folder. When force=true and a name conflict exists, the code deletes the destination folder to resolve the conflict.
php $this->requireVolumePermissionByFolder('deleteAssets', $folderToMove); $this->requireVolumePermissionByFolder('createFolders', $destinationFolder); $this->requireVolumePermissionByFolder('saveAssets', $destinationFolder);
src/controllers/AssetsController.php:L751-L753
Indexed destination conflicts are deleted via the Assets service:
php $assets->deleteFoldersByIds($existingFolder->id);
src/controllers/AssetsController.php:L798-L798
Unindexed destination conflicts are deleted directly in the volume filesystem:
php $targetVolume->deleteDirectory(rtrim($destinationFolder->path, '/') . '/' . $folderToMove->name);
src/controllers/AssetsController.php:L815
Impact
A user who cannot delete assets in a destination volume can still delete a destination folder and its contents by triggering a forced move into a conflicting name. This can cause asset loss, broken references in entries and fields that point to deleted assets, and operational disruption.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/craftcms/cmsto a version that resolves this vulnerability.Fixed in 4.17.14 - Upgrade
Upgrade
composer/craftcms/cmsto a version that resolves this vulnerability.Fixed in 5.9.21 - Upgrade
Upgrade
Craft CMSto a version that resolves this vulnerability.Fixed in 5.9.21 - Upgrade
Upgrade
Craft CMSto a version that resolves this vulnerability.Fixed in 4.17.14
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50282?
CVE-2026-50282 has a risk score of 37, indicating a medium severity vulnerability.
How do I fix CVE-2026-50282?
To remediate CVE-2026-50282, upgrade Craft CMS to version 5.9.21 or 4.17.14 or later.
What versions are affected by CVE-2026-50282?
CVE-2026-50282 affects Craft CMS versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above, prior to 4.17.14.
What type of issue is addressed by CVE-2026-50282?
CVE-2026-50282 addresses an authorization issue that allows unauthorized deletion of destination folders during forced moves.
Who is affected by CVE-2026-50282?
Users of Craft CMS versions listed in the vulnerability report who are utilizing folder move functionalities are at risk from CVE-2026-50282.