PT-2026-84671 · Craft Cms · Craft Cms

CVE-2026-84798

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Craft CMS versions 5.0.0-RC1 through 5.10.10
Description An authorization failure occurs in the actionDeleteForSite() function within the ElementsController. The system loads an element with checkForProvisionalDraft enabled and performs a deletion check against the user's provisional draft, which only verifies draft ownership. The deletion is then applied to the canonical element without a secondary permission check. Consequently, an authenticated user with viewEntries, viewPeerEntries, saveEntries, savePeerEntries, and editSite permissions, but without the deleteEntriesForSite permission, can permanently delete a canonical entry's site record. For single-site entries, this results in the total loss of the element and its content, which cannot be recovered from the recycle bin.
Recommendations Update Craft CMS to version 5.10.11.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84798
GHSA-5FH8-74J8-MVCP

Affected Products

Craft Cms