{"id":"GHSA-jq2f-59pj-p3m3","summary":"Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action","details":"## Summary\n\nThe `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group authorization for additions, it performs no equivalent authorization check for removals, so submitting an empty `groups` value removes all existing group memberships.\n\n## Affected Versions\n\n- Craft CMS 5.6.0 through 5.9.14 (latest release at time of report)\n- Regression introduced in 5.6.0 when the `viewUsers` permission was added\n- Prior to 5.6.0, `editedUser()` required `editUsers`, which implicitly protected this endpoint\n- Requires Pro edition or higher (the vulnerable code path is gated by `CmsEdition::Pro`)\n\n## Vulnerability Details\n\n### Root Cause\n\nThis is a **regression** introduced in Craft CMS 5.6.0 when the `viewUsers` permission was added. Before that change, `editedUser()` required `editUsers` permission for accessing other users’ data, which implicitly protected `actionSavePermissions()`. After the change, `actionSavePermissions()` became reachable for users with read-only access to other users, but the underlying group-saving logic still lacked authorization for group removals.\n\nThe vulnerability has two components:\n\n1. **`actionSavePermissions()` reachable with read-only access**: The action only requires a control panel request and delegates to `editedUser()`, which now only checks `viewUsers` — a permission explicitly documented as \"read-only access to user elements.\"\n\n2. **Asymmetric authorization in `_saveUserGroups()`**: The method checks `assignUserGroup` permission only when **adding** a user to a new group. When the `groups` parameter is an empty string (resulting in an empty array), the loop is skipped entirely, no authorization checks are run, and all group memberships are removed.\n\n### Prerequisites\n\n- Attacker has a control panel account with `accessCp` and `viewUsers` permissions only\n- Target user belongs to one or more user groups that grant additional permissions\n- Pro edition or higher\n\n### Attack Steps\n\n1. Attacker authenticates to the Control Panel\n2. Attacker sends a POST request to `actions/users/save-permissions` with:\n   - `userId` = target user's ID\n   - `groups` = `` (empty string)\n3. All group memberships for the target user are removed\n4. All permissions inherited from those groups are immediately revoked\n\n### Impact\n\n- **Privilege revocation**: An attacker can strip group-based permissions from arbitrary users, including accounts whose effective access derives from group membership\n- **Denial of access**: Users lose access to sections, volumes, and features that were granted through group membership\n- **Bypass of elevated session requirement**: Group removal does not trigger `requireElevatedSession()` (which is only triggered when new groups are added)","aliases":["CVE-2026-41128"],"modified":"2026-05-05T16:11:41.801372Z","published":"2026-04-14T23:34:52Z","database_specific":{"cwe_ids":["CWE-862"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-04-14T23:34:52Z","nvd_published_at":"2026-04-22T00:16:28Z"},"references":[{"type":"WEB","url":"https://github.com/craftcms/cms/security/advisories/GHSA-jq2f-59pj-p3m3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41128"},{"type":"WEB","url":"https://github.com/craftcms/cms/commit/b135384808ad43fcf8836a9dd9b877fb0087bc27"},{"type":"PACKAGE","url":"https://github.com/craftcms/cms"}],"affected":[{"package":{"name":"craftcms/cms","ecosystem":"Packagist","purl":"pkg:composer/craftcms/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.6.0"},{"fixed":"5.9.15"}]}],"versions":["5.6.0","5.6.0.1","5.6.0.2","5.6.1","5.6.10","5.6.10.1","5.6.10.2","5.6.11","5.6.12","5.6.13","5.6.14","5.6.15","5.6.16","5.6.17","5.6.2","5.6.3","5.6.4","5.6.5","5.6.5.1","5.6.6","5.6.7","5.6.8","5.6.9","5.6.9.1","5.7.0","5.7.0-beta.1","5.7.0-beta.2","5.7.1","5.7.1.1","5.7.10","5.7.11","5.7.2","5.7.3","5.7.4","5.7.5","5.7.6","5.7.7","5.7.8","5.7.8.1","5.7.8.2","5.7.9","5.8.0","5.8.1","5.8.10","5.8.11","5.8.12","5.8.13","5.8.13.1","5.8.13.2","5.8.14","5.8.15","5.8.16","5.8.17","5.8.18","5.8.19","5.8.2","5.8.20","5.8.21","5.8.22","5.8.23","5.8.3","5.8.4","5.8.5","5.8.6","5.8.7","5.8.8","5.8.9","5.9.0","5.9.0-beta.1","5.9.0-beta.2","5.9.1","5.9.10","5.9.11","5.9.12","5.9.13","5.9.14","5.9.2","5.9.3","5.9.4","5.9.5","5.9.6","5.9.7","5.9.8","5.9.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-jq2f-59pj-p3m3/GHSA-jq2f-59pj-p3m3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}