CVE-2026-86731
Deferred Deferred - Pending Action

Permission Escalation in Craft CMS via User Activation

Vulnerability report for CVE-2026-86731, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-19

Assigner: VulnCheck

Description

Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action). While the action requires the administrateUsers permission, it does not call requireAdmin() when the targeted user is an administrator, unlike the mirror action actionDeactivateUser. As a result, an authenticated control panel user who is not an administrator but holds the administrateUsers permission can activate a pending or deliberately deactivated administrator account, which can lead to permission escalation when combined with resetting that account's password. The issue is fixed in Craft CMS 5.10.12.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-19
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
craftcms craft_cms From 5.0.0 (inc) to 5.10.11 (inc)
craftcms craft_cms 5.10.12

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Craft CMS versions 5.0.0-RC1 through 5.10.11 have a flaw in the UsersController::actionActivateUser function. While the action requires the administrateUsers permission, it does not enforce admin-only access when activating another administrator account. This allows a non-admin user with the administrateUsers permission to activate a deactivated admin account, potentially leading to unauthorized privilege escalation.

Detection Guidance

Check Craft CMS version with composer show craftcms/craft or in the admin panel under Utilities > System Report. If version is between 5.0.0-RC1 and 5.10.11, the system is vulnerable.

Impact Analysis

If you are a Craft CMS user running versions 5.0.0-RC1 through 5.10.11, an attacker with access to the control panel but not full admin rights could exploit this to activate a disabled admin account. They could then reset the admin password and gain full administrative control over your site, compromising all data and functionality.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements under GDPR and HIPAA. If exploited, it may result in data breaches, triggering mandatory breach notifications and potential fines for non-compliance with these regulations.

Mitigation Strategies

Upgrade Craft CMS to version 5.10.12 or later immediately. Review user permissions to ensure only administrators have the administrateUsers permission.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86731. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart