6.5

CVE-2026-33159

Craft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted users

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, guest users can access Config Sync updater index, obtain signed data, and execute state-changing Config Sync actions (regenerate-yaml, apply-yaml-changes) without authentication. This issue has been patched in versions 4.17.8 and 5.9.14.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Craftcms ≫ Craft Cms Version > 4.0.0 < 4.17.8
Craftcms ≫ Craft Cms Version > 5.0.0 < 5.9.14
Craftcms ≫ Craft Cms Version 4.0.0 Update -
Craftcms ≫ Craft Cms Version 4.0.0 Update rc1
Craftcms ≫ Craft Cms Version 4.0.0 Update rc2
Craftcms ≫ Craft Cms Version 4.0.0 Update rc3
Craftcms ≫ Craft Cms Version 5.0.0 Update -
Craftcms ≫ Craft Cms Version 5.0.0 Update rc1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.223
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
security-advisories@github.com 6.9 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://github.com/craftcms/cms/releases/tag/4.17.8
Release Notes
https://github.com/craftcms/cms/releases/tag/5.9.14
Release Notes
https://github.com/craftcms/cms/security/advisories/GHSA-6mrr-q3pj-h53w
Vendor Advisory
https://github.com/craftcms/cms/commit/7f0ead833f7c2b91ae12003caad833479dd08592
Patch