CVE-2026-33162

Craft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section permissions

Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/entries/move-to-section, even when they do not have saveEntries:{sectionUid} permission for either source or destination section. This issue has been patched in version 5.9.14.


We have discovered 2 live websites that are affected by CVE-2026-33162.

Run a Free Instant Scan




Affected Software

Product  CrafterCMS
Category Content Management System
Vulnerable Domains2 live websites (100% of CrafterCMS install base)
Vulnerable Versions
  • from 5.3 through 5.9.14
Vulnerable Versions Count1 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-285 Improper Authorization



Details

  • Published - Mar 24, 2026
  • Updated - Mar 25, 2026

Website Distribution by Country

Number of websites using CVE-2026-33162
United States2 websites

Website Distribution by TLD

Number of websites using CVE-2026-33162
.com1 websites
.de1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-33162

Top websites that are affected by CVE-2026-33162. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.de United States**,***,***
***************.com United States**,***,***
See full domain list

FAQ

CVE-2026-33162 is Improper Authorization in CrafterCMS
A total of 2 websites have been identified as vulnerable to CVE-2026-33162, based on global website indexing conducted by WebTechSurvey.
The CrafterCMS is affected by the CVE-2026-33162 vulnerability.
CrafterCMS versions up to 5.9.14 are vulnerable to CVE-2026-33162.
CVE-2026-33162 is resolved in version 5.9.14 of CrafterCMS.