A AegiFlow
MEDIUMCVSS 5.3EPSS 0.2%

CVE-2026-14793

Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets

Published
2026-08-06
Modified
2026-08-06
EPSS percentile
13%
Aliases
GHSA-9p7c-v5x3-rfx8
Sources
github-advisory

Summary

The `reorder-sets` action in Craft CMS’s `GlobalsController` is missing the `requireAdmin()` check that the adjacent `save-set` and `delete-set` actions both enforce. Any authenticated control panel user can POST to `/actions/globals/reorder-sets` and permanently reorder all global sets in the project config, regardless of whether they have admin access. The reordering is written through to the project config and persists across requests. ## Description `GlobalsController` exposes three administrative actions for managing global set structure. Two of them gate on admin status; the third does not. ## Prerequisites - A Craft CMS instance with at least two global sets and a non-admin control panel user account. ## Impact A non-admin control panel user can reorder all global sets. While this does not expose or modify content, reordering global sets modifies the project config -- a versioned artifact that is typically committed to source control and deployed across environments. An attacker can create noise in the project config history, trigger config-sync conflicts, or manipulate the display order seen by all editors in the admin panel. The same non-admin user cannot create or delete global sets because those actions correctly enforce `requireAdmin()`.

Affected packages

EcosystemPackageAffected versionsFixed versions
Packagistcraftcms/cms4.18.1, 5.10.3

Remediation: Upgrade to 4.18.1 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.