Get real-time updates on Telegram
CVE-2026-32267: craftcms/cms >= 4.0.0-RC1, <= 4.17.5, >= 5.0.0-RC1, <= 5.9.11
CVE-2026-32267 affects craftcms/cms. EPSS 0.00487 (percentile 0.39873), scored 2026-10-06. Affected range: >= 4.0.0-RC1, <= 4.17.5. Fixed version: 4.17.6. Affected range: >= 5.0.0-RC1, <= 5.9.11. Fixed version: 5.9.12.
Affected technology
craftcms/cms · >= 4.0.0-RC1, <= 4.17.5
Vendor not specified by the source
craftcms/cms · >= 5.0.0-RC1, <= 5.9.11
Vendor not specified by the source
Description’s affected range: through UsersController->actionImpersonateWithToken() ### Summary A low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their privileges to admin by abusing `UsersController->actionImpersonateWithToken`
Component: Not specified by the source
What an attacker can do
The source reports that an attacker could gain higher privileges.
- Product
- craftcms/cms
- CCR priority
- 0.1 /100 (P5)
- EPSS
- 0.00487 · percentile 0.39873 · 2026-10-06
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-07 13:20:35.851963+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-32267.html