Summary
CVE-2026-84795 is an improper privilege management vulnerability in Craft CMS that allows an unauthenticated attacker to obtain full administrator access to the control panel. The flaw stems from a missing validation guard on the admin privilege flag during user account registration/reactivation. It affects Craft CMS 5.x installations with public registration enabled and carries a CVSS score of 9.2.
Technical details
- Root cause:
User::afterSave()writes theadminflag unconditionally, with no change-detection guard — unlike other sensitive account flags (active, pending, locked, suspended), which are protected against unauthorized modification. - Trigger conditions: public registration must be enabled; on Craft Pro, email verification must also be disabled. An attacker registers a new account using the email address of a previously deactivated administrator account.
- Mechanism: the system reuses the existing (inactive) user record tied to that email, which still carries its original admin status, and the missing validation lets that admin privilege transfer to the newly (re)activated account.
- Attack vector: network, unauthenticated, no user interaction required.
- Impact: full administrator access to the control panel, including user management, system settings, plugins, and site content.
Affected software
- Craft CMS 5.0.0-RC1 through versions prior to 5.10.11
- Exploitable configurations: Craft Team edition with
allowPublicRegistration=true; Craft Pro edition withallowPublicRegistration=trueandrequireEmailVerification=false
Severity
CVSS v3.1: 9.8 (Critical) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: 9.2 (Critical) — AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: upgrade Craft CMS to version 5.10.11 or later, where the admin flag change is properly guarded.
- If immediate patching isn’t possible: disable public registration (
allowPublicRegistration=false), or ensure email verification is required (requireEmailVerification=true) as an interim compensating control. - Audit user accounts for unexpected administrator privileges, particularly any recently created or reactivated accounts tied to previously deactivated admin email addresses.
How IONIX identifies potentially affected assets
IONIX matches the following signal against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Named HTTP response header (
x-powered-by):Craft CMS

