PT-2026-34219 · Craft Cms · Craft Cms
Published
2026-04-14
·
Updated
2026-04-25
·
CVE-2026-41128
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Craft CMS versions 5.6.0 through 5.9.14
Description
The 'actionSavePermissions()' endpoint allows a user possessing only
viewUsers permission to remove arbitrary users from all user groups. This occurs because the saveUserGroups() function enforces authorization for adding users to groups but fails to perform an equivalent check for removals. Consequently, submitting an empty groups value results in the removal of all existing group memberships.Recommendations
Update to version 5.9.15.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Craft Cms