Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-84796: Craft CMS lets attackers change content on other sites via GraphQL
CVE-2026-84796 · published 1 month ago
Summary
If you use Craft CMS version earlier than 5.10.11, a flaw in its GraphQL API can let someone with limited access modify, read, or delete content on sites they shouldn't. The problem occurs because the system does not properly check which site a request is targeting. Update to the latest version of Craft CMS to close this gap.
What to do
- Update craftcms cms to version 5.10.11 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| craftcms | cms | < 5.10.11 |
Original advisory text
GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/delete
Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to one site can read, modify, or delete entries across unauthorized sites by passing siteId directly in mutation arguments.
References
- https://packagist.org URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79990... Vendor Advisory
- https://github.com/craftcms/cms/releases/tag/5.10.11 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-79990 Vendor Advisory
- https://www.hckrt.com/hacktivity/HCKRT-XEQKMX Vendor Advisory
- https://github.com/craftcms/cms Product
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84796... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-84796 Vendor Advisory
- https://github.com/craftcms/cms/security/advisories/GHSA-3wcr-p33w-528f
- https://www.vulncheck.com/advisories/craft-cms-5.0.0-rc1-before-5.10.11-graphql-...
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published2 Sep 2026
Updated11 Oct 2026
First seen2 Sep 2026
Track software like this
Free during beta