What is CVE-2026-63669?
CVE-2026-63669 is a permission enforcement flaw in the page module's move() operation in ApostropheCMS versions prior to 4.32.0. Due to an improper archive condition check, an authenticated editor can move pages to a parent without the required '_create' permission. Immediate update to version 4.32.0 or later is required for mitigation.
Azərbaycanca: CVE-2026-63669 ApostropheCMS-in 4.32.0 öncəsi versiyalarında 'page module move()' əməliyyatında icazə yoxlaması zəifliyidir. Səhv səbəbindən autentifikasiya olunmuş redaktor, "_create" icazəsi olmasa belə səhifəni başqa yerə köçürə bilir. Təhlükəsizlik üçün dərhal 4.32.0 və ya daha yeni versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What action can an attacker perform by exploiting CVE-2026-63669 in ApostropheCMS?
This vulnerability allows an authenticated editor to move a page via the `page module move()` operation to a location that requires `_create` permission, without actually possessing that permission.
To which version of ApostropheCMS must one update to mitigate CVE-2026-63669?
The vulnerability exists in ApostropheCMS versions prior to 4.32.0, so you must update to version 4.32.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.