Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jq2f-59pj-p3m3 | Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action |
Wed, 22 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Apr 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Craftcms
Craftcms craftcms |
|
| Vendors & Products |
Craftcms
Craftcms craftcms |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group authorization for additions, it performs no equivalent authorization check for removals, so submitting an empty `groups` value removes all existing group memberships. Version 5.9.15 contains a patch. | |
| Title | Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-22T18:13:34.270Z
Reserved: 2026-04-17T12:59:15.737Z
Link: CVE-2026-41128
Updated: 2026-04-22T18:13:30.552Z
Status : Deferred
Published: 2026-04-22T00:16:28.593
Modified: 2026-04-22T20:26:20.563
Link: CVE-2026-41128
No data.
OpenCVE Enrichment
Updated: 2026-04-22T11:30:15Z
Github GHSA