CRITICAL 9.2 NVD
CVE-2026-84795
Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can regist
Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.
References
- https://github.com/craftcms/cms/security/advisories/GHSA-242m-9wq7-vhwq
- https://www.vulncheck.com/advisories/craft-cms-before-5.10.11-authentication-bypass-via-ad
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-09-02 via NVD.
Risk Timeline
CVE Disclosed2026-09-02 · -1 days ago
Remediation Resources
vulnfeed aggregates 11639 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.