Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-02 12:17
Updated : 2026-09-02 14:17
NVD link : CVE-2026-84795
Mitre link : CVE-2026-84795
CVE.ORG link : CVE-2026-84795
JSON object : View
Products Affected
No product.
CWE
CWE-269
Improper Privilege Management
