CVE-2026-84800: Craft CMS 5.0.0-RC1 before 5.10.11 File Overwrite via assets/replace-file

Published Sep 2, 2026
·
Updated

Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, the target asset is resolved by folder and filename after the permission checks execute, so the replacePeerFiles permission is never enforced. An authenticated low-privilege author with only the replaceFiles permission on a shared folder can overwrite the content of a peer's asset file (located in the same folder) with attacker-controlled bytes. Fixed in 5.10.11.

Affected Software

1 affected component
Craft CMS Craft CMS>=5.0.0-RC1<5.10.11

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Craft CMS to a version that resolves this vulnerability.

    Fixed in 5.10.11
  2. Compensating control

    Ensure low-privilege users who only have replaceFiles permission on a shared folder cannot trigger AssetsController::actionReplaceFile in a way that omits assetId (sourceAssetId + targetFilename without assetId), since authorization may not enforce replacePeerFiles permission.

Event History

Sep 2, 2026
CVE Published
via MITRE·11:11 AM
Data Sourced
via MITRE·11:11 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated low-privilege author is affected if they have replaceFiles permission on a shared asset folder. The attacker must be able to target a peer asset located in that same folder.

2

What does an attacker need to send to bypass the peer-file permission check?

The request must provide sourceAssetId and targetFilename while omitting assetId. In that path, the target asset is resolved only after permission checks, so replacePeerFiles is not enforced.

3

What is the impact of successful exploitation?

The attacker can overwrite a peer's asset file in the shared folder with attacker-controlled bytes. The issue affects integrity and can also cause limited availability impact.

4

Which versions are affected and what version fixes the issue?

Craft CMS versions from 5.0.0-RC1 through versions earlier than 5.10.11 are affected. The issue is fixed in version 5.10.11.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203