AUGUST 22, 2026
Live Feed
Back to database
Case File

CVE-2026-14794

MEDIUM · CVSS 4.3 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

Craft CMS versions up to 4.18.0.1 are vulnerable due to improper authorization in the actionGetNewUsersData function of the Charts Endpoint, which can be exploited remotely by manipulating the userGroupId argument. This flaw could allow unauthorized access to user data, posing a risk to sensitive information. Organizations using affected versions should prioritize upgrading to version 4.18.1 to mitigate this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-14794
Severity
MEDIUM
CVSS
4.3
EPSS
0.22%

Original NVD Description

A flaw has been found in Craft CMS up to 4.18.0.1. Affected by this vulnerability is the function actionGetNewUsersData of the file src/controllers/ChartsController.php of the component Charts Endpoint. This manipulation of the argument userGroupId causes improper authorization. The attack is possible to be carried out remotely. Upgrading to version 4.18.1 addresses this issue. Patch name: 9ee53efc1314e6aba32771c66a13e072a246f4ce. It is suggested to upgrade the affected component.