Impact
Craft CMS between 5.0.0‑RC1 and just before 5.11.0 has an improper authorization flaw in its GraphQL implementation. The draftCreator and revisionCreator fields are only gated by the elements.drafts:read or elements.revisions:read scopes and fail to enforce the user‑data scope that should be required for retrieving user information. As a result, any user who can query these GraphQL fields is able to pull full user elements, including email addresses, usernames, full names and postal addresses, exposing personally identifiable information that is normally protected. This flaw belongs to CWE‑200: Information Exposure through Improper Authorization.
Affected Systems
The vulnerability affects Craft CMS editions from the 5.0.0‑RC1 release through all versions prior to 5.11.0. Site administrators or editors who own drafts or revisions, or any client with a public GraphQL schema that includes the elements.drafts:read or elements.revisions:read scopes, can exploit it. All users whose details are returned can be harvested by such a client.
Risk and Exploitability
The flaw has a CVSS score of 8.7 and an EPSS score below 1%, indicating a high severity but still a low likelihood of exploitation at the time of analysis. The issue is not listed in the CISA KEV catalog. Attacks can be carried out via the unauthenticated or minimally‑privileged GraphQL endpoint, provided the public schema is enabled. Because only draft or revision scopes are necessary, an attacker can gather PII from any site with the vulnerable CMS version without needing higher privileges.
OpenCVE Enrichment