THREAT OPS › Threat News › [GHSA] GHSA-9p7c-v5x3-rfx8 (medium) — Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
[GHSA] GHSA-9p7c-v5x3-rfx8 (medium) — Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
GHSA-9p7c-v5x3-rfx8 Severity: medium CVE: CVE-2026-14793
Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
The `reorder-sets` action in Craft CMS’s `GlobalsController` is missing the `requireAdmin()` check that the adjacent `save-set` and `delete-set` actions both enforce. Any authenticated control panel user can POST to `/actions/globals/reorder-
MITRE ATT&CK techniques
- Control PanelT1218.002
Indicators of compromise
- CVE-2026-14793cve
Original source: https://github.com/advisories/GHSA-9p7c-v5x3-rfx8