Vulnerability Description
Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can query these relations to read usernames, email addresses, and full names of any content author or uploader including administrators.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/craftcms/cms/security/advisories/GHSA-4w9w-3x96-7ghp
- https://www.vulncheck.com/advisories/craft-cms-before-5.11.0-pii-disclosure-via-
FAQ
What is CVE-2026-84799?
CVE-2026-84799 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scope...
How severe is CVE-2026-84799?
CVE-2026-84799 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-84799?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.