ZeroHour

CVE-2026-84795

large

Privilege Escalation in Craft CMS via Deactivated Admin Flag

CVSS 4.0
9.2 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

Craft CMS before 5.10.11 contains an improper privilege management flaw (CWE-269) in which the admin flag of deactivated administrator accounts persists during user registration. When public registration is enabled and email verification is disabled, an unauthenticated attacker can register an account using the email address of a deactivated admin and inherit full administrator privileges. Successful exploitation grants complete control of the CMS, consistent with the high confidentiality, integrity, and availability impacts in the 9.2 (critical) CVSS 4.0 score. Only deployments running affected versions with public registration, disabled email verification, and at least one deactivated admin account are exploitable. No in-the-wild exploitation, public proof-of-concept, or KEV listing is currently known; EPSS estimates a 0.3% probability of exploitation in the next 30 days.

What to do: Upgrade Craft CMS to 5.10.11 or later. If upgrading is deferred, disable public user registration or re-enable email verification on registration, and delete or rename deactivated admin accounts so their email addresses cannot be claimed. Also audit recently self-registered users for unexpectedly inherited admin privileges.

Affected
Craft CMSall versions before 5.10.11
Estimated exposure
large≈ tens of thousands of Craft CMS sites — Public web-technology surveys and CMS fingerprinting typically detect tens of thousands of Craft CMS deployments, but only the subset with public registration enabled, email verification disabled, and a deactivated admin account can…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.

Weakness
CWE-269
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.