A vulnerability labeled as problematic has been found in Craft CMS up to 5.10.5. This affects the function
StructuresController.moveElement of the file src/controllers/StructuresController.php of the component Structures Controller. Executing a manipulation of the argument structureEditable can lead to improper privilege management.
This vulnerability is tracked as CVE-2026-72785. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.