Authorization Bypass in Craft CMS ElementsController for Specific Versions
CVE-2026-84798

7.1HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84798?

Craft CMS versions from 5.0.0-RC1 up to 5.10.10 are susceptible to an authorization bypass vulnerability in the ElementsController's actionDeleteForSite method. This flaw arises when the method performs an inadequate authorization check that mistakenly grants authenticated users the ability to permanently delete canonical entries without appropriate permissions. Specifically, users with specific permissions can execute a deletion against entries' records, which results in irrecoverable loss as it bypasses the typical precautions offered by Craft's recycle bin. This vulnerability poses a significant risk, as it enables unauthorized data manipulation in multiple environments.

Affected Version(s)

cms 5.0.0-RC1 < 5.10.11

cms 5.10.11

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.