CVE-2026-28781: Craft CMS: Entries Authorship Spoofing via Mass Assignment
(updated )
The entry creation process allows for Mass Assignment of the authorId attribute. A user with “Create Entries” permission can inject the authorIds[] (or authorId) parameter into the POST request, which the backend processes without verifying if the current user is authorized to assign authorship to others.
Normally, this field is not present in the request for users without the necessary permissions. By manually adding this parameter, an attacker can attribute the new entry to any user, including Admins. This effectively “spoofs” the authorship.
References
- github.com/advisories/GHSA-2xfc-g69j-x2mp
- github.com/craftcms/cms
- github.com/craftcms/cms/commit/830b403870cd784b47ae42a3f5a16e7ac2d7f5a8
- github.com/craftcms/cms/commit/c6dcbdffaf6ab3ffe77d317336684d83699f4542
- github.com/craftcms/cms/security/advisories/GHSA-2xfc-g69j-x2mp
- nvd.nist.gov/vuln/detail/CVE-2026-28781
Code Behaviors & Features
Detect and mitigate CVE-2026-28781 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →