High severity8.8NVD Advisory· Published Sep 2, 2026· Updated Sep 2, 2026
CVE-2026-84796
CVE-2026-84796
Description
Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to one site can read, modify, or delete entries across unauthorized sites by passing siteId directly in mutation arguments.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.