CVE-2026-84796 | Craft CMS up to 5.10.10 GraphQL Entry Mutation Resolver prepareArguments siteId improper authorization
A vulnerability was found in Craft CMS up to 5.10.10. It has been rated as critical. Affected by this issue is the function ArgumentManager::prepareArguments of the component GraphQL Entry Mutation Resolver. The manipulation of the argument siteId leads to improper authorization.
This vulnerability is traded as CVE-2026-84796. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More