---
id: CVE-2026-72785
title: >-
  Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization
  vulnerability
summary: >-
  Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization
  vulnerability. A control-panel user holding only the viewCategories permission
  (without saveCategories) for a category group can permanently modify that
  group's categ…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-863
vendor: craftcms
product: cms
affected:
  - cms >= 5.0.0-RC1 < 5.10.6
published: '2026-08-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:35.233'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72785'
references:
  - url: 'https://github.com/craftcms/cms/security/advisories/GHSA-xxpx-f366-4xpq'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/craft-cms-before-authorization-bypass-via-structures-move-element
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-11T18:06:18.985207Z'
epss: 0.00267
epssPercentile: 0.17245
ingestedAt: '2026-10-08T16:52:14.714Z'
---

## Overview

Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can permanently modify that group's category structure — reordering and re-parenting categories — via the structures/move-element action. The structureEditable flag is computed from the view permission rather than the save permission, and the StructuresController authorizes the mutating action on that read-time session grant without a save re-check. Because a category's URI is derived from its position in the structure, moving a category changes its URL and those of its descendants and can corrupt navigation menus built from the category taxonomy. The issue is fixed in 5.10.6.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
