Authorization Bypass in Craft CMS ElementsController for Specific Versions
CVE-2026-84798
7.1HIGH
What is CVE-2026-84798?
Craft CMS versions from 5.0.0-RC1 up to 5.10.10 are susceptible to an authorization bypass vulnerability in the ElementsController's actionDeleteForSite method. This flaw arises when the method performs an inadequate authorization check that mistakenly grants authenticated users the ability to permanently delete canonical entries without appropriate permissions. Specifically, users with specific permissions can execute a deletion against entries' records, which results in irrecoverable loss as it bypasses the typical precautions offered by Craft's recycle bin. This vulnerability poses a significant risk, as it enables unauthorized data manipulation in multiple environments.
Affected Version(s)
cms 5.0.0-RC1 < 5.10.11
cms 5.10.11
