THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9p7c-v5x3-rfx8 (medium) — Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets

[GHSA] GHSA-9p7c-v5x3-rfx8 (medium) — Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets

medgithub_advisoriesPublished 2026-08-06

GHSA-9p7c-v5x3-rfx8 Severity: medium CVE: CVE-2026-14793

Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets

The `reorder-sets` action in Craft CMS’s `GlobalsController` is missing the `requireAdmin()` check that the adjacent `save-set` and `delete-set` actions both enforce. Any authenticated control panel user can POST to `/actions/globals/reorder-

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9p7c-v5x3-rfx8