PT-2026-84671 · Craft Cms · Craft Cms
CVE-2026-84798
·
Published
2026-09-02
·
Updated
2026-09-02
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Craft CMS versions 5.0.0-RC1 through 5.10.10
Description
An authorization failure occurs in the
actionDeleteForSite() function within the ElementsController. The system loads an element with checkForProvisionalDraft enabled and performs a deletion check against the user's provisional draft, which only verifies draft ownership. The deletion is then applied to the canonical element without a secondary permission check. Consequently, an authenticated user with viewEntries, viewPeerEntries, saveEntries, savePeerEntries, and editSite permissions, but without the deleteEntriesForSite permission, can permanently delete a canonical entry's site record. For single-site entries, this results in the total loss of the element and its content, which cannot be recovered from the recycle bin.Recommendations
Update Craft CMS to version 5.10.11.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Craft Cms