Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to one site can read, modify, or delete entries across unauthorized sites by passing siteId directly in mutation arguments.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-02 12:17
Updated : 2026-09-02 16:17
NVD link : CVE-2026-84796
Mitre link : CVE-2026-84796
CVE.ORG link : CVE-2026-84796
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
