CVE-2026-50284 | Craft CMS up to 4.17.14/5.9.21 Sibling actionDeleteAsset Endpoint actionDeleteFolder authorization (GHSA-7h62-6v23-v8fm)

SecurityVulns

A vulnerability labeled as problematic has been found in Craft CMS up to 4.17.14/5.9.21. This affects the function theAssetsController::actionDeleteFolder of the component Sibling actionDeleteAsset Endpoint. Executing a manipulation can lead to missing authorization.

The identification of this vulnerability is CVE-2026-50284. The attack may be launched remotely. There is no exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More