{"id":"CVE-2026-14793","aliases":["GHSA-9p7c-v5x3-rfx8"],"title":"Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets","summary":"Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets","severity":"medium","cvss":4.3,"cwe":["CWE-862"],"vendor":"craftcms","product":"craftcms/cms","ecosystem":"composer","affected":["craftcms/cms >= 4.0.0-RC1, < 4.18.1","craftcms/cms >= 5.0.0-RC1, < 5.10.3"],"patched":["craftcms/cms 4.18.1","craftcms/cms 5.10.3"],"published":"2026-08-06","updated":"2026-08-06","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-9p7c-v5x3-rfx8","references":[{"url":"https://github.com/craftcms/cms/security/advisories/GHSA-9p7c-v5x3-rfx8"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14793"},{"url":"https://github.com/craftcms/cms/commit/9bd05c91e6a7e6da5e949ec41a31c220c059aa04"},{"url":"https://github.com/craftcms/cms/releases/tag/4.18.1"},{"url":"https://github.com/craftcms/cms/releases/tag/5.10.3"},{"url":"https://vuldb.com/cve/CVE-2026-14793"},{"url":"https://vuldb.com/submit/850792"},{"url":"https://vuldb.com/vuln/376387"},{"url":"https://github.com/advisories/GHSA-9p7c-v5x3-rfx8"}],"tags":["ghsa","composer"],"epss":0.00386,"epssPercentile":0.29866,"ingestedAt":"2026-08-06T21:04:21.883Z","slug":"CVE-2026-14793","body":"## Overview\n\nThe `reorder-sets` action in Craft CMS’s `GlobalsController` is missing the `requireAdmin()` check that the adjacent `save-set` and `delete-set` actions both enforce. Any authenticated control panel user can POST to `/actions/globals/reorder-sets` and permanently reorder all global sets in the project config, regardless of whether they have admin access. The reordering is written through to the project config and persists across requests.\n\n## Description\n\n`GlobalsController` exposes three administrative actions for managing global set structure. Two of them gate on admin status; the third does not.\n\n## Prerequisites\n\n- A Craft CMS instance with at least two global sets and a non-admin control panel user account.\n\n## Impact\n\nA non-admin control panel user can reorder all global sets. While this does not expose or modify content, reordering global sets modifies the project config -- a versioned artifact that is typically committed to source control and deployed across environments. An attacker can create noise in the project config history, trigger config-sync conflicts, or manipulate the display order seen by all editors in the admin panel. The same non-admin user cannot create or delete global sets because those actions correctly enforce `requireAdmin()`.\n\n## Affected packages\n\n- `craftcms/cms >= 4.0.0-RC1, < 4.18.1`\n- `craftcms/cms >= 5.0.0-RC1, < 5.10.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `craftcms/cms 4.18.1`\n- `craftcms/cms 5.10.3`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}