CVE-2026-84795

Summary

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.

Affected Software

VendorProductVersion RangeStatus
craftcmscms5.0.0-RC1 < 5.10.11affected
craftcmscms5.10.11unaffected

Weaknesses

  • CWE-269: Improper Privilege Management

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References