Unauthenticated Craft CMS users can trigger a database backup
Package
Affected versions
>= 5.0.0-RC1, <= 5.8.20
>= 3.0.0, <= 4.16.16
Patched versions
5.8.21
4.16.17
Description
Published to the GitHub Advisory Database
Jan 5, 2026
Reviewed
Jan 5, 2026
Published by the National Vulnerability Database
Jan 5, 2026
Last updated
Jan 9, 2026
Unauthenticated users can trigger database backup operations the
updater/backupaction, potentially leading to resource exhaustion or information disclosure.Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.
Craft 3 users should update to the latest Craft 4 and 5 releases, which include the fixes.
References:
craftcms/cms@f83d4e0
https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5821---2025-12-04
Affected Endpoints
POST /admin/actions/updater/backup(unauthenticated)Vulnerability Details
Root Cause
All
updater/*actions are explicitly configured with anonymous access:Attack Vector
/admin/actions/updater/backupbackupCommandReferences