Description
Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can query these relations to read usernames, email addresses, and full names of any content author or uploader including administrators.
Published: 2026-09-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Craft CMS before version 5.11.0 does not enforce user-group scope filters on native GraphQL user relations such as author, authors, uploader, draftCreator, and revisionCreator. Attackers possessing any scoped GraphQL token can query these relations and obtain usernames, email addresses, and full names of all content authors or uploaders, including administrators. These fields normally respect group membership but the filter is bypassed, allowing unconditional data exposure.

Affected Systems

Craft CMS, product by Craft CMS, is affected. Versions prior to 5.11.0 are vulnerable. The vulnerability was identified in the Craft CMS codebase hosted by Craft CMS.

Risk and Exploitability

The CVSS score is 5.3, indicating a moderate severity for confidentiality impact. The EPSS score is not available, but the vulnerability is not listed in the CISA KEV catalog. Exploitation requires possession of a GraphQL token with any scope granted by the site administrator. If such a token exists, an attacker can simply issue a GraphQL query to the vulnerable fields and retrieve PII. No need for elevated privileges or remote code execution; however, the exposed data can be used for phishing or account takeover attacks.

Generated by OpenCVE AI on September 2, 2026 at 12:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Craft CMS 5.11.0 or later, which includes the GraphQL user relation filter fix.
  • Revoke or limit any GraphQL tokens that provide broader scopes than necessary; apply minimal privilege principles.
  • Validate that all GraphQL queries no longer expose usernames, email addresses, or full names of users by performing test queries or penetration testing.

Generated by OpenCVE AI on September 2, 2026 at 12:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can query these relations to read usernames, email addresses, and full names of any content author or uploader including administrators.
Title Craft CMS before 5.11.0 PII Disclosure via GraphQL User Relations
First Time appeared Craftcms
Craftcms craft Cms
Weaknesses CWE-285
CPEs cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Vendors & Products Craftcms
Craftcms craft Cms
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Craftcms Craft Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-02T11:11:14.295Z

Reserved: 2026-09-02T10:19:06.331Z

Link: CVE-2026-84799

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-02T12:17:16.637

Modified: 2026-09-02T13:54:48.797

Link: CVE-2026-84799

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T13:30:05Z

Weaknesses