A vulnerability described as problematic has been identified in ApostropheCMS Apostrophe up to 4.31.x. Impacted is the function move of the component Page Module. Executing a manipulation of the argument _targetId/_position can lead to permission issues.

This vulnerability is handled as CVE-2026-63669. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.