An authenticated low-privileged user can call assets/preview-file for an asset they are not authorized to view and still receive preview response data (previewHtml) for that private asset.
The returned preview HTML included a private preview image route containing the target private assetId, even though canView was false for the attacker account.
assets/preview-file accepts a maliciously controlled assetId and renders preview output.This affects Craft installations with authenticated users of mixed privilege levels with private assets.
{
"cwe_ids": [
"CWE-200",
"CWE-639",
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-26T17:12:21Z",
"nvd_published_at": null,
"severity": "LOW"
}