GHSA-x76w-8c62-48mgMedium▾ SunlitCraft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A user with Control Panel access but without permission to view a target private asset can call assets/preview-thumb and receive preview HTML that contains a signed fallback transform link for that private asset.
Root-cause analysis:
assetId.Type:
Affected deployments:
Security consequence:
https://github.com/craftcms/cms/commit/d30df3112220db1ffd6726a3ed11857014c7fb27
craftcms/cms >= 4.0.0-RC1, <= 4.17.7craftcms/cms >= 5.0.0-RC1, <= 5.9.13Upgrade to a patched release:
craftcms/cms 4.17.8craftcms/cms 5.9.14Connected by shared product, vendor, weakness, or advisory.
GHSA-rvmm-v933-jgxqMediumCraft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
CVE-2026-14793Medium· 4.3Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
CVE-2026-55792MediumCraft CMS: Sensitive File Disclosure / Server-Side File Read
CVE-2026-50282HighCraft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
CVE-2026-50284HighCraft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets
GHSA-xxpx-f366-4xpqMediumCraft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element