CVE-2026-84795
Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84795.json, https://github.com/craftcms/cms/security/advisories/GHSA-242m-9wq7-vhwq, https://nvd.nist.gov/vuln/detail/CVE-2026-84795, https://www.vulncheck.com/advisories/craft-cms-before-5.10.11-authentication-bypass-via-admin-flag-inheritance