Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-84795

CRITICAL NVD
CVSS Score 9.8
Severity CRITICAL
Published Sep 02, 2026
Vendor unknown

Description

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.

References