CRITICAL 9.8 CVE-2026-84795 Published 2 Sept 2026

Craft CMS Admin Privilege Escalation

Worried this affects one of your servers?

Craft CMS versions before 5.10.11 have a vulnerability that allows attackers to gain administrator privileges.

When public registration is enabled and email verification is disabled, an attacker can register using an email address of a deactivated admin account, inheriting their administrator privileges.

Reference: CVE-2026-84795 on NVD

← Back to Security News