PT-2026-84668 · Craft Cms · Craft Cms

CVE-2026-84795

·

Published

2026-09-02

·

Updated

2026-09-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Craft CMS versions prior to 5.10.11
Description An issue exists where the system fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. If public registration is enabled and email verification is disabled, an attacker can register using the email address of a deactivated administrator to inherit administrator privileges.
Recommendations Update to version 5.10.11 or later.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84795
GHSA-242M-9WQ7-VHWQ

Affected Products

Craft Cms