PT-2026-94111 · Craft Cms · Craft Cms
CVE-2026-92594
·
Published
2026-09-16
·
Updated
2026-09-16
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Craft CMS versions 5.0.0-RC1 through 5.10.x
Description
Incorrect authorization occurs in the GraphQL
draftCreator and revisionCreator fields. Instead of requiring the user-data scope enforced by the canQueryUsers() function (usergroups.*:read), these fields are only restricted by the elements.drafts:read and elements.revisions:read scopes. The resolver returns a raw User element where the email, username, fullName, and addresses fields lack per-field authorization. Consequently, a client with only drafts or revisions scopes, including unauthenticated clients if the public GraphQL schema is enabled with those scopes, can harvest the email addresses, usernames, full names, and postal addresses of draft and revision creators, who are typically site editors and administrators.Recommendations
Update to version 5.11.0.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Craft Cms