CVE-2026-14793 | Craft CMS up to 4.18.0.1 reorder-sets Endpoint GlobalsController.php actionReorderSets authorization

SecurityVulns

A vulnerability labeled as critical has been found in Craft CMS up to 4.18.0.1. Affected is the function actionReorderSets of the file src/controllers/GlobalsController.php of the component reorder-sets Endpoint. The manipulation results in authorization bypass.

This vulnerability is identified as CVE-2026-14793. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More