CVE-2026-84796 UNKNOWN

CVE-2026-84796

Published: 2026-09-02

Description

Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to one site can read, modify, or delete entries across unauthorized sites by passing siteId directly in mutation arguments.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…