CVE-2026-84795: Craft CMS CMS
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.
Affected products
- Craft CMS CMS: from 5.0.0-RC1, before 5.10.11 (fixed in 5.10.11)
Published 2026-09-02. Last modified 2026-09-02.