PT-2026-43997 · Undefined · Undefined

0Xrixet

·

Published

2026-05-27

·

Updated

2026-05-27

·

CVE-2026-31266

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-31266

Affected Products

Undefined