PT-2026-84670 · Craft Cms · Craft Cms

CVE-2026-84797

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Craft CMS versions prior to 5.10.11
Description An authorization bypass exists in the ElementsController::actionDuplicate() function. Authenticated users with createEntries permission can delete provisional drafts belonging to other users. This is achieved by exploiting the deleteProvisionalDraft parameter, which lacks proper authorization checks, allowing unauthorized access to and deletion of in-progress content.
Recommendations Update Craft CMS to version 5.10.11 or later. As a temporary mitigation, restrict the createEntries permission to trusted users only.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84797
GHSA-2F55-H4XR-92P2

Affected Products

Craft Cms