CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-RVMM-V933-JGXQ

GHSA-rvmm-v933-jgxq: Missing Authorization Check in Craft CMS ChartsController

Alon Barad
Alon Barad
Software Engineer

Aug 7, 2026·6 min read·16 visits

Executive Summary (TL;DR)

Missing authorization in Craft CMS ChartsController allowed unauthorized access to sensitive time-series user metrics and registration demographics via `/actions/charts/get-new-users-data` prior to versions 4.18.1 and 5.10.3.

An authorization bypass vulnerability in Craft CMS allows unauthenticated or low-privileged users to query and obtain sensitive time-series user registration counts and demographic metrics. This is due to a missing authorization check inside the actionGetNewUsersData endpoint of the ChartsController class.

Vulnerability Overview

Craft CMS features an administrative dashboard containing visual metric components designed to provide administrators with quick insights into site usage. The ChartsController class coordinates data retrieval for these components. Under standard operations, charts display metadata such as user registrations, system activity, and asset counts. This data retrieval operates via specified action endpoints, which handle POST requests with structured query parameters.

Historically, user-related actions in Craft CMS are bound by authorization checks. Access to user directories, groups, and growth metrics should be restricted to users possessing the viewUsers permission. However, the endpoint /actions/charts/get-new-users-data did not validate if requests were initiated from within the authorized Control Panel context or by a user with explicit privileges.

The lack of validation exposed a vulnerable attack surface. An attacker with standard authenticated access could query this endpoint directly. The resulting response disclosed time-series registration metrics and user group distribution patterns, circumventing intended security constraints.

Root Cause Analysis

The fundamental issue stems from a missing authorization context check inside ChartsController::actionGetNewUsersData(). Craft CMS allows routing to controller actions via specific frontend action parameters or backend Control Panel routes. If a controller action fails to explicitly assert its routing domain, it may remain accessible to frontend actions.

In the vulnerable codebase, actionGetNewUsersData() accepted inbound requests without verifying that they originated from the Control Panel (requireCpRequest()). Consequently, the action was exposed on the public-facing interface to any authenticated user session, bypassing the restrictive access controls defined for the Control Panel directory.

Furthermore, the action failed to enforce the explicit viewUsers permission. In multi-tenant or role-restricted environments, users are often assigned low-privilege roles, such as "Content Editor". These roles are granted base Control Panel access (accessCp) but are restricted from accessing user administration features. The absent permission validation allowed these restricted accounts to directly query the database for registration statistics.

Code Analysis

To understand the flaw, we analyze the implementation of actionGetNewUsersData within src/controllers/ChartsController.php. Prior to the security patch, the method immediately extracted request parameters without verifying the origin of the route or the privileges of the active session.

// Vulnerable Code Path
public function actionGetNewUsersData(): Response
{
    // Missing: $this->requireCpRequest() or explicit permission checks
 
    $userGroupId = $this->request->getBodyParam('userGroupId');
    $startDateParam = $this->request->getRequiredBodyParam('startDate');
    $endDateParam = $this->request->getRequiredBodyParam('endDate');
    // ... execution of user query ...
}

The remediation committed in 9ee53efc1314e6aba32771c66a13e072a246f4ce introduced a validation call at the entry point of the controller action. By calling $this->requireCpRequest(), the application now verifies that the request context matches the admin Control Panel.

// Patched Code Path
public function actionGetNewUsersData(): Response
{
    // Verifies the request originates from the Control Panel context
    $this->requireCpRequest();
 
    $userGroupId = $this->request->getBodyParam('userGroupId');
    $startDateParam = $this->request->getRequiredBodyParam('startDate');
    $endDateParam = $this->request->getRequiredBodyParam('endDate');
    // ... execution of user query ...
}

While this patch blocks unauthenticated external requests and frontend-only users, a minor residual gap remains. The call to requireCpRequest() does not validate the specific viewUsers permission. Control Panel users with minimal privileges (accessCp only) can still access the route. If a deployment relies on granular user group isolation, these low-privilege users can query stats about other user groups, though direct PII is not leaked.

Exploitation & Proof-of-Concept

Exploitation requires a valid session on the target application. This session can belong to a low-privileged user possessing basic Control Panel privileges. The attacker first authenticates and extracts the active CSRF token (CRAFT_CSRF_TOKEN) from the document object model.

The attacker then constructs a structured HTTP POST request to the action endpoint. The request payload must include valid startDate and endDate parameters, alongside an optional userGroupId parameter. Specifying different IDs allows the attacker to query registration statistics for specific target user groups sequentially.

curl -X POST "https://example.com/actions/charts/get-new-users-data" \
     -H "Content-Type: application/x-www-form-urlencoded" \
     -H "Cookie: CraftSessionId=9ee53efc1314e6aba32771c66a13e0" \
     --data-urlencode "CRAFT_CSRF_TOKEN=abc123xyz" \
     --data-urlencode "startDate=2026-01-01" \
     --data-urlencode "endDate=2026-12-31" \
     --data-urlencode "userGroupId=2"

Upon execution, the server processes the database query and returns a JSON response containing the registration counts grouped chronologically. This response leaks aggregate site metrics. An attacker can use this data to perform reconnaissance, mapping user registration trends and estimating the sizes of internal user groups.

Impact Assessment

The immediate impact of this vulnerability is unauthorized information disclosure. While the endpoint does not leak high-severity sensitive data like plaintext credentials, password hashes, or full names, it exposes system-wide user growth data. An attacker can determine historical user sign-up patterns and estimate platform adoption rates.

In enterprise and multi-tenant environments, user demographics and registration velocity constitute proprietary business intelligence. For instance, an unauthorized competitor with low-privileged access could map active growth cycles. Additionally, mapping specific user group IDs allows attackers to assess which administrative or standard groups are actively expanding.

The vulnerability represents a failure in depth-of-defense design. It illustrates how standard controller endpoints can accidentally expose sensitive data metrics if authorization checks are only enforced at the UI layer rather than the API layer. Remediation is required to maintain complete data confidentiality across role-based access control policies.

Remediation & Detection

Administrators should immediately deploy updated packages. For installations running the 4.x branch, upgrade to version 4.18.1 or higher. For installations running the 5.x branch, upgrade to version 5.10.3 or higher. These releases implement the necessary request context verification.

If immediate patching is not feasible, restrict route access at the web server layer. WAF rules can block incoming requests to /actions/charts/get-new-users-data or equivalent rewrite patterns if they originate from unauthorized IP ranges or lack admin session cookies. However, patching via Composer remains the recommended path.

To detect previous exploitation attempts, review application logs for POST requests directed to the target action path. Pay particular attention to requests submitted by users who lack administrative rights. Correlating these requests with user group IDs in the query payload helps identify unauthorized intelligence-gathering activities.

Official Patches

Pixel & TonicOfficial Fix Commit on GitHub
Pixel & TonicCraft CMS v4.18.1 Release Notes
Pixel & TonicCraft CMS v5.10.3 Release Notes

Fix Analysis (1)

Technical Appendix

CVSS Score
5.3/ 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected Systems

Craft CMS

Affected Versions Detail

Product
Affected Versions
Fixed Version
Craft CMS
Pixel & Tonic
>= 4.0.0-RC1, < 4.18.14.18.1
Craft CMS
Pixel & Tonic
>= 5.0.0-RC1, < 5.10.35.10.3
AttributeDetail
CWE IDCWE-862
Attack VectorNetwork
CVSS5.3 (Medium)
Exploit Statuspoc
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1020Automated Exfiltration
Exfiltration
T1082System Information Discovery
Discovery
CWE-862
Missing Authorization

The application does not perform an authorization check when an actor attempts to access the actionGetNewUsersData resource.

Vulnerability Timeline

Pixel & Tonic committed the security fix in repository.
2026-05-22
Craft CMS released versions 4.18.1 and 5.10.3.
2026-05-25
Security Advisory GHSA-rvmm-v933-jgxq published.
2026-08-06

References & Sources

  • [1]GitHub Security Advisory GHSA-rvmm-v933-jgxq
  • [2]Raw Code Patch File
  • [3]Craft CMS Core Repository

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•43 minutes ago•CVE-2026-107212
7.5

CVE-2026-107212: CPU Exhaustion Denial of Service via Look-Ahead Row Parsing in Excelize

An algorithmic complexity vulnerability (CWE-770) in the Excelize library allows remote attackers to cause resource exhaustion (100% CPU usage) via a crafted Microsoft Excel spreadsheet. This occurs because the look-ahead row index parsing in Rows.Columns() fails to enforce upper boundary limits, enabling an out-of-bounds row index to trigger an infinite seek loop inside the Rows iterator.

Alon Barad
Alon Barad
4 views•6 min read
•about 2 hours ago•CVE-2026-105647
4.0

CVE-2026-105647: Server-Side Request Forgery via Favicon Probing in Ghost CMS

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Ghost CMS from version 6.54.1 to 6.65.0. The vulnerability stems from a validation bypass in the favicon resolution logic within the bookmark-fetching subsystem, which allows remote, unauthenticated attackers to trigger arbitrary HTTP requests to the local host and internal networks. This bypass circumvents the custom DNS-level IP blocklist controls configured globally in the application.

Alon Barad
Alon Barad
3 views•8 min read
•about 3 hours ago•CVE-2026-106450
5.3

CVE-2026-106450: Denial of Service via Eager Resource Allocation in lz4-java LZ4FrameInputStream

A resource allocation vulnerability (CWE-770) in lz4-java before version 1.11.4 allows an unauthenticated remote attacker to trigger CPU exhaustion and high garbage collection overhead by streaming empty concatenated LZ4 frames.

Alon Barad
Alon Barad
5 views•8 min read
•about 4 hours ago•CVE-2026-106449
3.7

CVE-2026-106449: Stack Overflow via Uncontrolled Recursion in yawkat lz4-java

A Denial of Service (DoS) vulnerability exists in the yawkat fork of lz4-java prior to version 1.11.4. Under specific non-default configurations (stopOnEmptyBlock = false), parsing crafted streams with a large sequence of contiguous empty LZ4 blocks triggers uncontrolled recursion inside the LZ4BlockInputStream.refill() method, causing stack exhaustion and thread termination.

Alon Barad
Alon Barad
4 views•6 min read
•about 4 hours ago•CVE-2026-76485
9.8

CVE-2026-76485: Remote Code Execution in Cisco NX-OS VXLAN OAM (NGOAM)

CVE-2026-76485 is a critical stack-based buffer overflow vulnerability in the VXLAN OAM (NGOAM) parsing component of Cisco NX-OS Software. The flaw enables an unauthenticated, remote attacker to execute arbitrary code with root privileges or trigger a denial of service on affected Nexus switches. This vulnerability is triggered through crafted packets sent to an IP interface. No workarounds are currently available to mitigate the vulnerability while preserving the NGOAM functionality. Cisco has published software patches to address this flaw.

Alon Barad
Alon Barad
7 views•6 min read
•about 5 hours ago•CVE-2026-106451
7.3

CVE-2026-106451: Local Privilege Escalation via JNI Extraction TOCTOU in lz4-java

A local privilege escalation and code execution vulnerability exists in the yawkat fork of lz4-java when extracting its bundled JNI shared library into the system temporary directory. Predictable path derivation and lack of exclusive file creation flags allow a local attacker to hijack library loading via a race condition.

Alon Barad
Alon Barad
6 views•6 min read