SB2026090749 - Incorrect authorization in WPGraphQL



SB2026090749 - Incorrect authorization in WPGraphQL

Published: September 7, 2026

Security Bulletin ID SB2026090749
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incorrect authorization (CVE-ID: N/A)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper authorization in the WPGraphQL UserMutation role-handling logic when processing a roles array in createUser or updateUser GraphQL mutations. A remote privileged user can submit a crafted mutation with the administrator role first in the roles array to escalate privileges.

The API may report that the role assignment was denied even though the role has already been applied.


Remediation

Install update from vendor's website.