CVE-2026-72785 | Craft CMS up to 5.10.5 Structures Controller StructuresController.php StructuresController.moveElement structureEditable privileges management

SecurityVulns

A vulnerability labeled as problematic has been found in Craft CMS up to 5.10.5. This affects the function StructuresController.moveElement of the file src/controllers/StructuresController.php of the component Structures Controller. Executing a manipulation of the argument structureEditable can lead to improper privilege management.

This vulnerability is tracked as CVE-2026-72785. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More