GHSA-9p7c-v5x3-rfx8
Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
빠른 조치
GHSA-9p7c-v5x3-rfx8 — craftcms/cms: 아래 명령으로 수정 버전으로 올리세요.
composer require craftcms/cms:^4.18.1 상세
The `reorder-sets` action in Craft CMS’s `GlobalsController` is missing the `requireAdmin()` check that the adjacent `save-set` and `delete-set` actions both enforce. Any authenticated control panel user can POST to `/actions/globals/reorder-sets` and permanently reorder all global sets in the project config, regardless of whether they have admin access. The reordering is written through to the project config and persists across requests.
## Description
`GlobalsController` exposes three administrative actions for managing global set structure. Two of them gate on admin status; the third does not.
## Prerequisites
- A Craft CMS instance with at least two global sets and a non-admin control panel user account.
## Impact
A non-admin control panel user can reorder all global sets. While this does not expose or modify content, reordering global sets modifies the project config -- a versioned artifact that is typically committed to source control and deployed across environments. An attacker can create noise in the project config history, trigger config-sync conflicts, or manipulate the display order seen by all editors in the admin panel. The same non-admin user cannot create or delete global sets because those actions correctly enforce `requireAdmin()`.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
참고
- https://github.com/craftcms/cms/security/advisories/GHSA-9p7c-v5x3-rfx8 [WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-14793 [ADVISORY]
- https://github.com/craftcms/cms/commit/9bd05c91e6a7e6da5e949ec41a31c220c059aa04 [WEB]
- https://github.com/craftcms/cms [PACKAGE]
- https://github.com/craftcms/cms/releases/tag/4.18.1 [WEB]
- https://github.com/craftcms/cms/releases/tag/5.10.3 [WEB]
- https://vuldb.com/cve/CVE-2026-14793 [WEB]
- https://vuldb.com/submit/850792 [WEB]
- https://vuldb.com/vuln/376387 [WEB]