PT-2026-34219 · Craft Cms · Craft Cms

Published

2026-04-14

·

Updated

2026-04-25

·

CVE-2026-41128

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Craft CMS versions 5.6.0 through 5.9.14
Description The 'actionSavePermissions()' endpoint allows a user possessing only viewUsers permission to remove arbitrary users from all user groups. This occurs because the saveUserGroups() function enforces authorization for adding users to groups but fails to perform an equivalent check for removals. Consequently, submitting an empty groups value results in the removal of all existing group memberships.
Recommendations Update to version 5.9.15.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41128
GHSA-JQ2F-59PJ-P3M3

Affected Products

Craft Cms