CVE-2026-92589 | craftcms Craft CMS up to 5.10.12 Nested Elements Reorder reorder offset privileges management

SecurityVulns

A vulnerability labeled as problematic has been found in craftcms Craft CMS up to 5.10.12. Affected is an unknown function of the file actions/nested-elements/reorder of the component Nested Elements Reorder. Such manipulation of the argument offset leads to improper privilege management.

This vulnerability is uniquely identified as CVE-2026-92589. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More