Impact
Craft CMS releases prior to version 5.10.11 contain an authorization bypass flaw in ElementsController::actionDuplicate() that lets an authenticated user with the createEntries permission delete a peer’s provisional draft. The deleteProvisionalDraft parameter is not properly validated, allowing the attacker to remove another user’s unsaved content without authorization. The affected user’s draft can be deleted, potentially exposing in‑progress content or disrupting their editorial workflow.
Affected Systems
The vulnerability affects all installations of Craft CMS before 5.10.11, including the 5.0.0‑RC1 release. Users running any pre‑5.10.11 build are susceptible, while any installation upgraded to 5.10.11 or later has the patch applied.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. Exploitation requires an authenticated user who already holds the createEntries permission and access to the duplicate action URL. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is currently uncertain, but the impact on confidentiality and integrity of draft content merits prompt remediation.
OpenCVE Enrichment