CRITICAL
9.8 CVE-2026-84795 Published 2 Sept 2026
Craft CMS Admin Privilege Escalation
Worried this affects one of your servers?
Craft CMS versions before 5.10.11 have a vulnerability that allows attackers to gain administrator privileges.
When public registration is enabled and email verification is disabled, an attacker can register using an email address of a deactivated admin account, inheriting their administrator privileges.
Reference: CVE-2026-84795 on NVD
← Back to Security News