Junglewise Threat Intelligence

CVE-2026-84799: Craft CMS GraphQL improper authorization in user relations

CVE-2026-84799 · Severity: medium · CVSS 4.3 · Published 2026-09-02

Technologies: Craft CMS.

Executive brief

Craft CMS is a popular content management system used to manage website content and user data. Before version 5.11.0, a flaw in the GraphQL API fails to properly restrict access to user information—specifically names, email addresses, and usernames of all content authors and administrators—even when API tokens are scoped to limited user groups. An attacker with a restricted API token can query this user data across the entire site, leading to exposure of sensitive personal information.

Technical details

The vulnerability is an improper authorization flaw (CWE-285) in Craft CMS's GraphQL implementation. The root cause lies in native element-to-User relations (author, authors, uploader, draftCreator, revisionCreator fields) that resolve directly without user-group scope enforcement. While the top-level users query correctly checks canQueryUsers() scope, the native relations bypass this check and resolve directly from the source element in src/gql/base/ObjectType.php. An attacker with a GraphQL token scoped to a specific user group or the public schema can leverage this to read PII of any content author or uploader, including site administrators. The flaw affects Craft CMS versions 5.0.0-RC1 through 5.10.x; version 5.11.0 and later apply proper user-group filtering to these relations.

Affected products

  • Craft CMS 5.0.0-RC1 through 5.10.x

Timeline

  • 2026-08-18: disclosed: GitHub security advisory published
  • 2026-09-02: patched: Fixed in version 5.11.0
  • 2026-09-02: advisory: NVD and VulnCheck advisory published

References