You must have administrator access, and ALLOW_ADMIN_CHANGES
must be enabled for this to work.
https://craftcms.com/knowledge-base/securing-craft#set-allowAdminChanges-to-false-in-production
Note: This is a follow-up to GHSA-f3cw-hg6r-chfv
Users should update to the patched versions (4.16.6 and 5.8.7) to mitigate the issue.
References: https://github.com/craftcms/cms/pull/17612
{ "cwe_ids": [ "CWE-1336", "CWE-22", "CWE-94" ], "github_reviewed": true, "nvd_published_at": "2025-08-25T18:15:31Z", "github_reviewed_at": "2025-08-25T20:42:45Z", "severity": "MODERATE" }