Impact
Craft CMS versions through 5.10.11 lack an administrative guard in a user activation endpoint. The action requires the administrateUsers permission but does not verify that the target user is an administrator. An authenticated non‑administrator who has the administrateUsers permission can activate an administrator account that has been pending or deliberately deactivated. When this account’s password is reset, the attacker can assume full administrative control. This demonstrates a missing authorization weakness (CWE-862) that can lead to privilege escalation and compromise of the entire control panel.
Affected Systems
The vulnerability affects Craft CMS by craftcms, specifically all releases from 5.0.0‑RC1 through 5.10.11. Users should confirm whether their installation falls within this range and upgrade if so.
Risk and Exploitability
The CVSS score of 7.1 categorizes the issue as high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector requires an authenticated user with the administrateUsers permission, meaning it is exploitable only by internally privileged accounts. Nevertheless, once exploited the attacker gains full administrative access, making the risk significant particularly in organizations with many users granted administrateUsers rights.
OpenCVE Enrichment