PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-92589 craftcms CVE debrief

CVE-2026-92589 is a broken access control vulnerability in Craft CMS 5.0.0 through 5.10.12, fixed in 5.10.13. An authenticated control panel user with view-only access can reorder Matrix blocks or Addresses for content they are denied save access to. This issue allows unauthorized modification of content, potentially impacting data integrity. Defenders should prioritize verifying exposure and applying the patch to prevent exploitation. The vulnerability is located in the nested-elements reorder endpoint, which grants unauthorized access to modify content for users with view-only permissions. To address this issue, defenders should verify if the system uses Craft CMS 5.0.0-5.10.12,

Vendor
craftcms
Product
cms
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-18
Advisory published
2026-09-16
Advisory updated
2026-09-18

Who should care

Defenders managing Craft CMS installations, particularly those with multiple users or content contributors, should assess exposure and apply the patch. This includes reviewing system configurations, user permissions, and monitoring for unauthorized modifications to content. Additionally, defenders should prioritize verifying exposure and applying the patch to prevent exploitation. The vulnerability allows unauthorized modification of content, potentially

Why it matters

CVE-2026-92589 is a broken access control vulnerability in Craft CMS 5.0.0-5.10.12 that allows view-only users to reorder Matrix blocks or Addresses for content they cannot save. Defenders should prioritize verifying exposure and applying the patch.

  • Potential unauthorized modification of content
  • Need to verify exposure and apply patch
  • Risk of data integrity compromise

Technical summary

The nested-elements reorder endpoint in Craft CMS 5.0.0-5.10.12 grants unauthorized access to modify content for users with view-only permissions. This allows view-only users to reorder Matrix blocks or Addresses for content they are explicitly denied save access to. The vulnerability is fixed in Craft CMS 5.10.13. To address this issue, defenders should prioritize verifying exposure and applying the patch. The CVE record and NVD entry provide details on the vulnerability, but its exploitation and impact require further verification.

Defensive priority

Defenders should prioritize verifying exposure and applying the patch, as the vulnerability allows unauthorized modification of content.

Recommended defensive actions

  • Verify if the system uses Craft CMS 5.0.0-5.10.12 and apply patch 5.10.13 if vulnerable
  • Restrict access to the control panel to trusted users
  • Monitor for unauthorized modifications to content
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but its exploitation and impact require further verification. The vulnerability allows view-only users to reorder Matrix blocks or Addresses for content they cannot save. To verify exposure, defenders should review system configurations, user permissions, and monitor for unauthorized modifications to content. The CVE Program and NVD entries provide source-provided CVE metadata and official vulnerability details, respectively. Additional sources may be necessary to

Sources and references

Verified primary and authoritative sources

  • CVE-2026-92589 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-92589

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-92589 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92589

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.