CVE-2026-84796 | Craft CMS up to 5.10.10 GraphQL Entry Mutation Resolver prepareArguments siteId improper authorization

SecurityVulns

A vulnerability was found in Craft CMS up to 5.10.10. It has been rated as critical. Affected by this issue is the function ArgumentManager::prepareArguments of the component GraphQL Entry Mutation Resolver. The manipulation of the argument siteId leads to improper authorization.

This vulnerability is traded as CVE-2026-84796. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More