Improper privilege management in Craft CMS - #VU144277

 

Improper privilege management in Craft CMS - #VU144277

Published: August 19, 2026


Vulnerability identifier: #VU144277
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain administrator access.

The vulnerability exists due to improper privilege management in User::afterSave() when registering a new account with the email address of a previously deactivated administrator account. A remote attacker can register a crafted account to gain administrator access.

Exploitation requires public registration to be enabled, and email verification to be disabled.


Affected software

Craft CMS

Remediation

Install security update from vendor's website.

Craft CMS - update to 5.10.11

External References

Related Security Bulletins