CVE-2026-84796

Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to one site can read, modify, or delete entries across unauthorized sites by passing siteId directly in mutation arguments.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 12:17

Updated : 2026-09-02 16:17


NVD link : CVE-2026-84796

Mitre link : CVE-2026-84796

CVE.ORG link : CVE-2026-84796


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key