


Perceptive Security
SOC/SIEM Consultancy

Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads …
Published:
2 september 2026 om 00:00:00
Alert date:
2 september 2026 om 15:03:46
Source:
nvd.nist.gov
Web Technologies, Identity & Access
A critical authorization bypass vulnerability exists in Craft CMS versions >= 5.0.0-RC1 and < 5.10.11. The flaw resides in ElementsController::actionDeleteForSite(), which incorrectly checks deletion permissions against a user's provisional draft rather than the canonical element. This allows authenticated users with certain permissions (viewEntries, viewPeerEntries, saveEntries, savePeerEntries, editSite) but without the deleteEntriesForSite permission to hard-delete canonical entry site records. For single-site entries, this results in complete and irrecoverable deletion of the element and its content, bypassing Craft's recycle bin. The vulnerability stems from missing re-authorization after the provisional draft check propagates the deletion to the canonical element. Users should upgrade to Craft CMS 5.10.11 or later to remediate this issue.
Technical details
Mitigation steps:
Affected products:
Craft CMS >= 5.0.0-RC1 and < 5.10.11
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-84798
https://github.com/craftcms/cms/security/advisories/GHSA-5fh8-74j8-mvcp
https://www.vulncheck.com/advisories/craft-cms-before-5.10.11-authorization-bypass-via-actiondeleteforsite
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
