Site Scope Bypass in Craft CMS Affecting GraphQL Entry Mutation Resolvers
CVE-2026-84796
8.7HIGH
What is CVE-2026-84796?
Craft CMS versions prior to 5.10.11 are vulnerable to a site scope bypass issue within GraphQL entry mutation resolvers. This vulnerability arises from insufficient validation of the siteId parameter within ArgumentManager::prepareArguments(). Consequently, attackers possessing tokens limited to a specific site can exploit this flaw, allowing them to read, modify, or delete entries across unauthorized sites by manipulating the siteId directly in mutation arguments. This poses a significant risk to the integrity and confidentiality of data within Craft CMS.
Affected Version(s)
cms 5.0.0-RC1 < 5.10.11
cms 5.10.11
