highVulnerability

CVE-2026-50282

We have identified an authorization issue in Craft CMS where a forced folder move can delete a conflicting destination folder without destination delete permission. ### Description Craft CMS’s `craft\\controllers\\AssetsController::actionMoveFolder()` supports moving an asset folder into a destination parent folder. If a folder with the same name already exists at the destination, the action can be called with `force=true` to overwrite the destination. The permission checks for this action allow: - `deleteAssets:<sourceVolumeUid>` for the folder being moved - `createFolders:<destVolumeUid>` for the destination parent folder - `saveAssets:<destVolumeUid>` for the destination parent folder The action does not require `deleteAssets` on the destination volume or destination conflict folder. When `force=true` and a name conflict exists, the code deletes the destination folder to resolve the conflict. ```php $this->requireVolumePermissionByFolder('deleteAssets', $folderToMove); $this->requireVolumePermissionByFolder('createFolders', $destinationFolder); $this->requireVolumePermissionByFolder('saveAssets', $destinationFolder); ``` [*src/controllers/AssetsController.php:L751-L753*](https://github.com/craftcms/cms/blob/5.x/src/controllers/AssetsController.php#L751-L753) Indexed destination conflicts are deleted via the Assets service: ```php $assets->deleteFoldersByIds($existingFolder->id); ``` [*src/controllers/AssetsController.php:L798-L798*](https://github.com/craftcms/cms/blob/5.x/src/controllers/AssetsController.php#L798-L798) Unindexed destination conflicts are deleted directly in the volume filesystem: ```php $targetVolume->deleteDirectory(rtrim($destinationFolder->path, '/') . '/' . $folderToMove->name); ``` [*src/controllers/AssetsController.php:L815*](https://github.com/craftcms/cms/blob/5.x/src/controllers/AssetsController.php#L815) ### Impact A user who cannot delete assets in a destination volume can still delete a destination folder and its c

Properties

ghsa_id
GHSA-3w32-23wj-rxg3
summary
Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
severity
high
epss_score
0.00207
cve_id
CVE-2026-50282
is_ghsa_only
false
ghsa_published
2026-07-02T20:03:58Z
source_url
https://github.com/advisories/GHSA-3w32-23wj-rxg3
epss_percentile
0.1113
ghsa_updated
2026-07-02T20:03:59Z

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/craftcms/cms

AFFECTS (1)

[Software]composer/craftcms/cms

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-50282 — Ninja Signal Threat Intelligence | Ninja Signal