Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schema’s allowed sites. The query path (ElementResolverprepareElementQuery) correctly calls prepareArguments()`, so queries to unauthorized sites return empty. But mutations bypass this entirely — an attacker with a token scoped to Site A can create, modify, or delete entries in Site B by passing siteId in the mutations argument. | |
| Title | GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/delete | |
| First Time appeared |
Craftcms
Craftcms cms |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Craftcms
Craftcms cms |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Hackrate
Published:
Updated: 2026-09-02T17:53:23.468Z
Reserved: 2026-08-25T16:39:03.171Z
Link: CVE-2026-79990
No data.
Status : Received
Published: 2026-09-02T15:17:42.473
Modified: 2026-09-02T18:21:25.867
Link: CVE-2026-79990
No data.
OpenCVE Enrichment
No data.
-
CWE-639
Authorization Bypass Through User-Controlled Key