Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-84795: Craft CMS lets new users inherit admin rights
CVE-2026-84795 · published 1 day ago
Summary
Versions of Craft CMS older than 5.10.11 can let a person sign up using the email address of a former administrator and automatically receive admin privileges, but only when public registration is allowed and email verification is turned off. This could give an attacker full control of the site. Update Craft CMS to the latest version and consider requiring email verification or disabling public registration to prevent it.
What to do
- Update craftcms cms to version 5.10.11 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| craftcms | cms | < 5.10.11 |
Original advisory text
Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email a...
Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.
Severity
9.2
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.2 (NVD)
Type
CWE-269Improper Privilege Management
Timeline
Published2 Sep 2026
Updated2 Sep 2026
First seen2 Sep 2026
Monitor software like this
Free during beta