Unauthenticated users can trigger database backup operations the updater/backup action, potentially leading to resource exhaustion or information disclosure.
Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.
Craft 3 users should update to the latest Craft 4 and 5 releases, which include the fixes.
References:
https://github.com/craftcms/cms/commit/f83d4e0c6b906743206b4747db4abf8164b8da39
https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5821---2025-12-04
POST /admin/actions/updater/backup (unauthenticated)All updater/* actions are explicitly configured with anonymous access:
// BaseUpdaterController.php
protected array|bool|int $allowAnonymous = self::ALLOW_ANONYMOUS_LIVE | self::ALLOW_ANONYMOUS_OFFLINE;
/admin/actions/updater/backupbackupCommand{
"github_reviewed": true,
"github_reviewed_at": "2026-01-05T18:49:56Z",
"severity": "HIGH",
"nvd_published_at": "2026-01-05T22:15:52Z",
"cwe_ids": [
"CWE-202",
"CWE-770"
]
}