CVE Vulnerabilities

CVE-2025-68456

Exposure of Sensitive Information Through Data Queries

Published: Jan 05, 2026 | Modified: Jan 12, 2026
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations via specific admin actions, potentially leading to resource exhaustion or information disclosure. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue. Craft 3 users should update to the latest Craft 4 and 5 releases, which include the fixes.

Weakness

When trying to keep information confidential, an attacker can often infer some of the information by using statistics.

Affected Software

NameVendorStart VersionEnd Version
Craft_cmsCraftcms3.0.0 (including)4.16.17 (excluding)
Craft_cmsCraftcms5.0.1 (including)5.8.21 (excluding)
Craft_cmsCraftcms5.0.0 (including)5.0.0 (including)
Craft_cmsCraftcms5.0.0-rc1 (including)5.0.0-rc1 (including)

Potential Mitigations

References