Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).
Metrics
Affected Vendors & Products
References
History
Thu, 28 May 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Craftcms
Craftcms craft Cms |
|
| Vendors & Products |
Craftcms
Craftcms craft Cms |
Wed, 27 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Missing Authorization on Craft CMS Migration Endpoint | |
| Weaknesses | CWE-284 |
Wed, 27 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Wed, 27 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-05-27T00:00:00.000Z
Updated: 2026-05-27T18:26:58.308Z
Reserved: 2026-03-09T00:00:00.000Z
Link: CVE-2026-31266
Updated: 2026-05-27T18:26:52.675Z
Status : Deferred
Published: 2026-05-27T15:16:26.467
Modified: 2026-05-27T20:00:46.020
Link: CVE-2026-31266
No data.