PatchSiren cyber security CVE debrief
CVE-2026-92589 craftcms CVE debrief
CVE-2026-92589 is a broken access control vulnerability in Craft CMS 5.0.0 through 5.10.12, fixed in 5.10.13. An authenticated control panel user with view-only access can reorder Matrix blocks or Addresses for content they are denied save access to. This issue allows unauthorized modification of content, potentially impacting data integrity. Defenders should prioritize verifying exposure and applying the patch to prevent exploitation. The vulnerability is located in the nested-elements reorder endpoint, which grants unauthorized access to modify content for users with view-only permissions. To address this issue, defenders should verify if the system uses Craft CMS 5.0.0-5.10.12,
- Vendor
- craftcms
- Product
- cms
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-09-18
Who should care
Defenders managing Craft CMS installations, particularly those with multiple users or content contributors, should assess exposure and apply the patch. This includes reviewing system configurations, user permissions, and monitoring for unauthorized modifications to content. Additionally, defenders should prioritize verifying exposure and applying the patch to prevent exploitation. The vulnerability allows unauthorized modification of content, potentially
Why it matters
CVE-2026-92589 is a broken access control vulnerability in Craft CMS 5.0.0-5.10.12 that allows view-only users to reorder Matrix blocks or Addresses for content they cannot save. Defenders should prioritize verifying exposure and applying the patch.
- Potential unauthorized modification of content
- Need to verify exposure and apply patch
- Risk of data integrity compromise
Technical summary
The nested-elements reorder endpoint in Craft CMS 5.0.0-5.10.12 grants unauthorized access to modify content for users with view-only permissions. This allows view-only users to reorder Matrix blocks or Addresses for content they are explicitly denied save access to. The vulnerability is fixed in Craft CMS 5.10.13. To address this issue, defenders should prioritize verifying exposure and applying the patch. The CVE record and NVD entry provide details on the vulnerability, but its exploitation and impact require further verification.
Defensive priority
Defenders should prioritize verifying exposure and applying the patch, as the vulnerability allows unauthorized modification of content.
Recommended defensive actions
- Verify if the system uses Craft CMS 5.0.0-5.10.12 and apply patch 5.10.13 if vulnerable
- Restrict access to the control panel to trusted users
- Monitor for unauthorized modifications to content
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but its exploitation and impact require further verification. The vulnerability allows view-only users to reorder Matrix blocks or Addresses for content they cannot save. To verify exposure, defenders should review system configurations, user permissions, and monitor for unauthorized modifications to content. The CVE Program and NVD entries provide source-provided CVE metadata and official vulnerability details, respectively. Additional sources may be necessary to
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92589 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92589
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92589 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92589
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/craftcms/cms/security/advisories/GHSA-6fp2-8j9w-7mj8
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/craft-cms-5.0.0-before-5.10.13-broken-access-control-via-nested-elements-reorder
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.