Description
Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are gated only on the elements.drafts:read / elements.revisions:read scopes, and their resolver returns a raw User element whose email, username, fullName, and addresses fields have no per-field authorization. A client holding only the drafts or revisions scope — including an unauthenticated client when the operator has enabled the public GraphQL schema with those scopes — can therefore harvest the email addresses, usernames, full names, and postal addresses of all draft/revision creators (typically site editors and administrators). The issue is fixed in 5.11.0.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

Craft CMS between 5.0.0‑RC1 and just before 5.11.0 has an improper authorization flaw in its GraphQL implementation. The draftCreator and revisionCreator fields are only gated by the elements.drafts:read or elements.revisions:read scopes and fail to enforce the user‑data scope that should be required for retrieving user information. As a result, any user who can query these GraphQL fields is able to pull full user elements, including email addresses, usernames, full names and postal addresses, exposing personally identifiable information that is normally protected. This flaw belongs to CWE‑200: Information Exposure through Improper Authorization.

Affected Systems

The vulnerability affects Craft CMS editions from the 5.0.0‑RC1 release through all versions prior to 5.11.0. Site administrators or editors who own drafts or revisions, or any client with a public GraphQL schema that includes the elements.drafts:read or elements.revisions:read scopes, can exploit it. All users whose details are returned can be harvested by such a client.

Risk and Exploitability

The flaw has a CVSS score of 8.7 and an EPSS score below 1%, indicating a high severity but still a low likelihood of exploitation at the time of analysis. The issue is not listed in the CISA KEV catalog. Attacks can be carried out via the unauthenticated or minimally‑privileged GraphQL endpoint, provided the public schema is enabled. Because only draft or revision scopes are necessary, an attacker can gather PII from any site with the vulnerable CMS version without needing higher privileges.

Generated by OpenCVE AI on September 18, 2026 at 05:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Craft CMS 5.11.0 or later, which fixes the authorization logic for GraphQL.
  • If an upgrade is not immediately feasible, disable the public GraphQL schema or remove the elements.drafts:read and elements.revisions:read scopes from unauthenticated clients to prevent the leaked data from being queried.
  • Continuously monitor for updates from craftcms and ensure that any future GraphQL‑related changes enforce the user‑data scope before release.

Generated by OpenCVE AI on September 18, 2026 at 05:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are gated only on the elements.drafts:read / elements.revisions:read scopes, and their resolver returns a raw User element whose email, username, fullName, and addresses fields have no per-field authorization. A client holding only the drafts or revisions scope — including an unauthenticated client when the operator has enabled the public GraphQL schema with those scopes — can therefore harvest the email addresses, usernames, full names, and postal addresses of all draft/revision creators (typically site editors and administrators). The issue is fixed in 5.11.0.
Title Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL
First Time appeared Craftcms
Craftcms craft Cms
Weaknesses CWE-200
CPEs cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Vendors & Products Craftcms
Craftcms craft Cms
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Craftcms Craft Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T20:08:12.977Z

Reserved: 2026-09-16T13:47:49.170Z

Link: CVE-2026-92594

cve-icon Vulnrichment

Updated: 2026-09-18T20:08:09.421Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T22:18:30.283

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-92594

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:30:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor