Craft CMS Missing Authorization Vulnerability in Migrate Endpoint

Vulnerability

A missing authorization vulnerability has been identified in Craft CMS versions through 5.9.5. This vulnerability exists in the migrate endpoint of the application.

Impact

Exploitation of this vulnerability allows for authentication bypass, enabling unauthorized users to access functionalities that require authentication.

Reproduction

To reproduce this vulnerability, send a POST request to the '/actions/app/migrate' endpoint without proper authorization. This can be done using a tool like curl.

Remediation

Users are advised to update Craft CMS to version 5.9.6 or later, where this vulnerability has been addressed.

Added: May 27, 2026, 5:35 PM
Updated: May 27, 2026, 5:35 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
9.7
remediation
0.0
relevance
9.2
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.