GHSA-rvmm-v933-jgxq
`ChartsController::actionGetNewUsersData()` at `/actions/charts/get-new-users-data` is missing a `requirePermission('viewUsers')` authorization check. Any authenticated control panel user, regardless of permissions beyond `accessCp`, can POST to this endpoint to receive time-series user registration counts for the entire site or for an arbitrary user group ID. The `viewUsers` permission is consistently required throughout the control panel before exposing user-related data, but this action enforces only the base `accessCp` check inherited from the framework. Each call returns the total count of users who joined the specified group in the requested period. ## Impact Any control panel user with only `accessCp` permission can obtain the total number of registered users and their registration date distribution across any time window. In installations with multiple editor roles, this allows a low-privilege control panel user to infer user group sizes and registration trends that would normally require the `viewUsers` permission to access. No user PII (name, email, password) is disclosed; only aggregate counts and timestamps are returned. Confidentiality impact is low. No integrity or availability impact.
Properties
- ghsa_id
- GHSA-rvmm-v933-jgxq
- severity
- medium
- summary
- Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
- cve_id
- GHSA-rvmm-v933-jgxq
- is_ghsa_only
- true
- ghsa_published
- 2026-08-06T21:42:58Z
- source_url
- https://github.com/advisories/GHSA-rvmm-v933-jgxq
- ghsa_updated
- 2026-08-06T21:42:58Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph