Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish entries to unauthorized sections by overwriting the sectionId attribute after initial authorization checks, bypassing the destination section permission validation. | |
| Title | Craft CMS before 5.10.11 Broken Access Control via element-indexes | |
| First Time appeared |
Craftcms
Craftcms craft Cms |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Craftcms
Craftcms craft Cms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-02T12:43:16.441Z
Reserved: 2026-09-02T10:19:06.330Z
Link: CVE-2026-84792
Updated: 2026-09-02T12:42:56.405Z
Status : Deferred
Published: 2026-09-02T12:17:15.670
Modified: 2026-09-02T13:54:48.797
Link: CVE-2026-84792
No data.
OpenCVE Enrichment
Updated: 2026-09-02T14:00:09Z
-
CWE-862
Missing Authorization