Craft CMS Authenticated Privilege Escalation via assets/preview-thumb Info Disclosure
Security Advisory
GHSA-x76w-8c62-48mg
Low
Craft CMS
Affected:
- craftcms/cms >= 4.0.0-RC1, <= 4.17.7
- craftcms/cms >= 5.0.0-RC1, <= 5.9.13
Fixed in:
- 4.17.8
- 5.9.14
Referenced CVEs:
CVE-2026-56384 · 4.3
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.