PT-2026-84669 · Craft Cms · Craft Cms

CVE-2026-84796

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Craft CMS versions prior to 5.10.11
Description GraphQL entry mutation resolvers fail to validate the siteId through the prepareArguments() function in the ArgumentManager class. This allows an attacker using a token scoped to a specific site to bypass site scoping by passing a different siteId directly in mutation arguments, enabling the unauthorized reading, modification, or deletion of entries across other sites.
Recommendations Update to version 5.10.11.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84796
GHSA-3WCR-P33W-528F

Affected Products

Craft Cms