CVE-2026-84792
Received Received - Intake

Broken Access Control in Craft CMS Prior to 5.10.11

Vulnerability report for CVE-2026-84792, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: VulnCheck

Description

Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish entries to unauthorized sections by overwriting the sectionId attribute after initial authorization checks, bypassing the destination section permission validation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
craftcms craft_cms to 5.10.11 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Craft CMS versions before 5.10.11 have a broken access control flaw in the element-indexes/save-elements endpoint. This allows control panel users with limited section permissions to move entries into sections they cannot edit by overwriting the sectionId attribute after initial authorization checks. The system fails to revalidate permissions after the section change, bypassing destination section restrictions.

Detection Guidance

Monitor Craft CMS control panel activity for unauthorized section changes. Check logs for POST requests to the element-indexes/save-elements endpoint with modified sectionId values. Review entries moved to sections where the user lacks permissions.

Impact Analysis

Attackers with low-privilege control panel access can relocate or publish entries into unauthorized sections. This enables content integrity violations, privilege escalation, and potential injection of misleading or harmful content into restricted sections. All site visitors may be affected by the unauthorized content changes.

Compliance Impact

This vulnerability could lead to unauthorized content modifications, violating data integrity and access control requirements in GDPR and HIPAA. Unauthorized section changes may expose sensitive data or permit content tampering, potentially resulting in compliance violations and regulatory penalties.

Mitigation Strategies

Upgrade Craft CMS to version 5.10.11 or later immediately. Review user permissions to ensure no unauthorized section changes are possible. Monitor for suspicious activity in the control panel.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84792. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart