CVE-2026-84792: Craft CMS before 5.10.11 Broken Access Control via element-indexes
Published Sep 2, 2026
·Updated
Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish entries to unauthorized sections by overwriting the sectionId attribute after initial authorization checks, bypassing the destination section permission validation.
Affected Software
1 affected component
Craft CMS Craft CMS<5.10.11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Craft CMSto a version that resolves this vulnerability.Fixed in 5.10.11
Event History
Sep 2, 2026
CVE Published
via MITRE·11:11 AM
Data Sourced
via MITRE·11:11 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Can an unauthenticated attacker exploit this issue?
No. Exploitation requires a low-privileged control panel user account.
2
Does exploiting this vulnerability require user interaction?
No. The vulnerability is rated with no user interaction required.