CVE-2026-84802 | craftcms Craft CMS up to 5.10.11 AssetsController actionMoveInfo folderIds information disclosure

SecurityVulns

A vulnerability labeled as problematic has been found in craftcms Craft CMS up to 5.10.11. Affected by this issue is the function AssetsController::actionMoveInfo of the component AssetsController. The manipulation of the argument folderIds results in information disclosure.

This vulnerability was named CVE-2026-84802. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.VulDB Recent EntriesRead More