SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-84795

CRITICAL · CVSS 9.8 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Craft CMS versions prior to 5.10.11 are vulnerable due to inadequate validation of the admin flag during user registration, which allows attackers to register using an email address from a deactivated admin account. This flaw can lead to unauthorized users gaining administrator privileges, particularly when public registration is enabled and email verification is disabled. Organizations using Craft CMS should prioritize patching this vulnerability to prevent potential exploitation and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84795
Severity
CRITICAL
CVSS
9.8
EPSS
0.28%

Original NVD Description

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.