CVE-2026-84797 | Craft CMS up to 5.10.10 ElementsController actionDuplicate deleteProvisionalDraft authorization

SecurityVulns

A vulnerability categorized as critical has been discovered in Craft CMS up to 5.10.10. This affects the function ElementsController::actionDuplicate of the component ElementsController. The manipulation of the argument deleteProvisionalDraft results in authorization bypass.

This vulnerability is known as CVE-2026-84797. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More