Craft CMS Access Control Vulnerability in Asset Transformation Endpoint

Vulnerability

An access control vulnerability has been identified in Craft CMS versions 4.0.0-RC1 prior to 4.17.8 and 5.0.0-RC1 prior to 5.9.14. The issue allows unauthenticated users to access private assets by calling the 'assets/generate-transform' endpoint with a private asset ID. The endpoint, which is anonymous, does not verify authorization for individual assets before providing a transform URL. This oversight enables guest users to retrieve content from private assets if the transform output is accessible.

Impact

Exploitation of this vulnerability allows unauthorized users to access and download transformed image bytes from private assets, leading to unauthorized information disclosure.

Remediation

Users can upgrade to Craft CMS versions 4.17.8 or 5.9.14 to address this vulnerability.

Added: Mar 24, 2026, 6:31 PM
Updated: Mar 24, 2026, 6:31 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
9.0
remediation
7.7
relevance
4.6
threat
3.2
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.