CVE-2026-84795: Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance

Published Sep 2, 2026
·
Updated

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.

Affected Software

1 affected component
Craft CMS Craft CMS<5.10.11

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Craft CMS to a version that resolves this vulnerability.

    Fixed in 5.10.11

Event History

Sep 2, 2026
CVE Published
via MITRE·11:11 AM
Data Sourced
via MITRE·11:11 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments running Craft CMS before 5.10.11 are exposed when public user registration is enabled and email verification is disabled. Exploitation also depends on the presence of a deactivated administrator account whose email address can be used for registration.

2

What does an attacker need to exploit the vulnerability?

An attacker needs network access to the public registration function and must register using the email address of a deactivated administrator account. No existing account privileges or user interaction are required under the affected configuration.

3

What can be done if upgrading is not immediately possible?

Disable public user registration or enable email verification to prevent the described registration path. Review deactivated administrator accounts, particularly their email addresses, because those accounts are relevant to exploitation.

4

How can administrators assess whether they may already be affected?

Check whether the installation is running a version before 5.10.11, whether public registration is enabled, and whether email verification is disabled. Also review registrations associated with email addresses belonging to deactivated administrator accounts and verify whether any such users have administrator privileges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203