Description
Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish entries to unauthorized sections by overwriting the sectionId attribute after initial authorization checks, bypassing the destination section permission validation.
Published: 2026-09-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Craft CMS versions prior to 5.10.11 contain a broken access control flaw in the element-indexes/save-elements API. The flaw allows a control panel user to modify the sectionId of an entry after the initial authorization check, effectively moving entries into sections that the user is not permitted to edit. This results in unauthorized publishing or relocation of content and can be used to bypass permissions and potentially expose sensitive information or disrupt site operations.

Affected Systems

Craft CMS installations running any version older than 5.10.11 of the core CMS product. The vulnerability is specific to the element-indexes feature, which is provided by the core Craft CMS platform.

Risk and Exploitability

The CVSS score is 5.3, indicating a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers require only control panel user access and the ability to submit requests to the element-indexes endpoint. From the description, it is inferred that the only prerequisite is limited section permissions; the attacker can relabel entries to sections for which they have no edit rights. The attack vector is a locally authenticated or web‑based CSRF attack with minimal technical skill needed beyond knowledge of element‑indexes URLs.

Generated by OpenCVE AI on September 2, 2026 at 12:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Craft CMS to version 5.10.11 or later.
  • Revoke or restrict control panel permissions for sections that users should not be able to edit, following the principle of least privilege.
  • Review any custom plugins or extensions that alter element‑indexes behavior and temporarily disable or patch them until a secure version is available.

Generated by OpenCVE AI on September 2, 2026 at 12:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish entries to unauthorized sections by overwriting the sectionId attribute after initial authorization checks, bypassing the destination section permission validation.
Title Craft CMS before 5.10.11 Broken Access Control via element-indexes
First Time appeared Craftcms
Craftcms craft Cms
Weaknesses CWE-862
CPEs cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Vendors & Products Craftcms
Craftcms craft Cms
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Craftcms Craft Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-02T12:43:16.441Z

Reserved: 2026-09-02T10:19:06.330Z

Link: CVE-2026-84792

cve-icon Vulnrichment

Updated: 2026-09-02T12:42:56.405Z

cve-icon NVD

Status : Deferred

Published: 2026-09-02T12:17:15.670

Modified: 2026-09-02T13:54:48.797

Link: CVE-2026-84792

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T13:00:13Z

Weaknesses