Executive brief
Craft CMS is a popular content management system used to manage website content and multi-site publishing. A permission flaw allows authenticated users with limited editing rights to permanently delete content entries or site-specific content records without proper authorization checks, bypassing the intended access controls. This data loss is irreversible and cannot be recovered through Craft's recycle bin.
Technical details
The vulnerability is a missing authorization check (CWE-862) in ElementsController::actionDeleteForSite(). The method loads an element with checkForProvisionalDraft enabled, which returns the user's provisional draft if one exists. It then performs a canDeleteForSite() authorization check against this draft rather than the canonical element; the draft check only verifies creator ownership (which always passes since the user created their own draft). The deletion is then propagated to the canonical element without a second authorization check. An authenticated attacker with viewEntries, viewPeerEntries, saveEntries, savePeerEntries, and editSite permissions (but no deleteEntriesForSite permission) can hard-delete canonical entry records. For multi-site entries, the site-specific record is deleted; for single-site entries, the entire element and content are removed permanently. The vulnerability requires network access and authenticated session but no user interaction. A patch is available in version 5.10.11.
Affected products
- Craft CMS >= 5.0.0-RC1, < 5.10.11
Timeline
- 2026-08-18: disclosed: GHSA-5fh8-74j8-mvcp published
- 2026-09-02: advisory: CVE-2026-84798 published
- 2026-09-02: patched: Patch released in version 5.10.11