Authorization Bypass Vulnerability in Craft CMS by Pixel & Tonic
CVE-2026-84797
5.3MEDIUM
What is CVE-2026-84797?
Craft CMS versions prior to 5.10.11 are susceptible to an authorization bypass vulnerability in the ElementsController::actionDuplicate() method. This flaw enables authenticated users possessing createEntries permission to delete peer provisional drafts. By exploiting the deleteProvisionalDraft parameter, attackers can delete unsaved drafts of other users without proper authorization checks, compromising the integrity of in-progress content and workflows.
Affected Version(s)
cms 5.0.0-RC1 < 5.10.11
cms 5.10.11
