CVE-2026-25497 | Craft CMS up to 5.8.21 authorization (GHSA-fxp3-g6gw-4r4v)
A vulnerability identified as critical has been detected in Craft CMS up to 5.8.21. This affects an unknown part. Performing a manipulation results in authorization bypass.
This vulnerability is cataloged as CVE-2026-25497. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.