Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-84796: Craft CMS lets attackers change content on other sites via GraphQL

CVE-2026-84796 · published 1 month ago
Summary

If you use Craft CMS version earlier than 5.10.11, a flaw in its GraphQL API can let someone with limited access modify, read, or delete content on sites they shouldn't. The problem occurs because the system does not properly check which site a request is targeting. Update to the latest version of Craft CMS to close this gap.

What to do
  • Update craftcms cms to version 5.10.11 or later.
Affected software
VendorProductAffected versions
craftcms cms < 5.10.11
Original advisory text
GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/delete
Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to one site can read, modify, or delete entries across unauthorized sites by passing siteId directly in mutation arguments.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.7 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published2 Sep 2026
Updated11 Oct 2026
First seen2 Sep 2026
Sources
CVE-2026-84796 · MITRE
Track software like this
Free during beta