CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2026-32267: craftcms/cms >= 4.0.0-RC1, <= 4.17.5, >= 5.0.0-RC1, <= 5.9.11

CVE-2026-32267 affects craftcms/cms. EPSS 0.00487 (percentile 0.39873), scored 2026-10-06. Affected range: >= 4.0.0-RC1, <= 4.17.5. Fixed version: 4.17.6. Affected range: >= 5.0.0-RC1, <= 5.9.11. Fixed version: 5.9.12.

Affected technology

craftcms/cms · >= 4.0.0-RC1, <= 4.17.5
Vendor not specified by the source

craftcms/cms · >= 5.0.0-RC1, <= 5.9.11
Vendor not specified by the source

Description’s affected range: through UsersController->actionImpersonateWithToken() ### Summary A low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their privileges to admin by abusing `UsersController->actionImpersonateWithToken`

Component: Not specified by the source

What an attacker can do

The source reports that an attacker could gain higher privileges.

Published

Product
craftcms/cms
CCR priority
0.1 /100 (P5)
EPSS
0.00487 · percentile 0.39873 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-32267.html