CVE-2026-14793 | Craft CMS up to 4.18.0.1 reorder-sets Endpoint GlobalsController.php actionReorderSets authorization
A vulnerability labeled as critical has been found in Craft CMS up to 4.18.0.1. Affected is the function actionReorderSets of the file src/controllers/GlobalsController.php of the component reorder-sets Endpoint. The manipulation results in authorization bypass.
This vulnerability is identified as CVE-2026-14793. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More