Executive brief
Craft CMS, a popular headless content management system, uses GraphQL to manage content across multiple sites. A flaw in the saveEntry and deleteEntry mutations allows an attacker with API access to one site to create, modify, or delete content in other sites by directly specifying a different site ID. This bypasses the intended multi-tenant access controls, potentially compromising content integrity and confidentiality across separate site instances.
Technical details
The vulnerability is an authorization bypass in Craft CMS's GraphQL entry mutation resolvers. The saveEntry and deleteEntry mutations read the siteId parameter directly from $arguments without invoking the ArgumentManager's prepareArguments() method, which normally enforces site-scope filtering via array_intersect. In contrast, query resolvers (ElementResolver) correctly call prepareArguments(), ensuring unauthorized site access is blocked. An attacker with a GraphQL token scoped to Site A can bypass this check by passing a siteId belonging to Site B in the mutation payload. No elevated privileges or user interaction is required beyond having a valid API token. The patch requires mutations to consistently apply ArgumentManager's site-filtering logic before processing siteId arguments.
Affected products
- Craft CMS <UNKNOWN>
Timeline
- 2026-09-02: disclosed