CVE-2026-84795

Source
https://cve.org/CVERecord?id=CVE-2026-84795
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84795.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-84795
Aliases
  • GHSA-242m-9wq7-vhwq
Published
2026-09-02T11:11:11.270Z
Modified
2026-09-04T03:47:27.025516575Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance
Details

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84795.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-269"
    ]
}
References

Affected packages

Git / github.com/craftcms/cms

Affected ranges

Type
GIT
Repo
https://github.com/craftcms/cms
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "5.0.0-RC1"
        },
        {
            "fixed": "5.10.11"
        },
        {
            "introduced": "0"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84795.json"