PT-2026-94111 · Craft Cms · Craft Cms

CVE-2026-92594

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Craft CMS versions 5.0.0-RC1 through 5.10.x
Description Incorrect authorization occurs in the GraphQL draftCreator and revisionCreator fields. Instead of requiring the user-data scope enforced by the canQueryUsers() function (usergroups.*:read), these fields are only restricted by the elements.drafts:read and elements.revisions:read scopes. The resolver returns a raw User element where the email, username, fullName, and addresses fields lack per-field authorization. Consequently, a client with only drafts or revisions scopes, including unauthenticated clients if the public GraphQL schema is enabled with those scopes, can harvest the email addresses, usernames, full names, and postal addresses of draft and revision creators, who are typically site editors and administrators.
Recommendations Update to version 5.11.0.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92594
GHSA-PCMV-C398-GC5M

Affected Products

Craft Cms