CVE-2026-84797 | Craft CMS up to 5.10.10 ElementsController actionDuplicate deleteProvisionalDraft authorization
A vulnerability categorized as critical has been discovered in Craft CMS up to 5.10.10. This affects the function ElementsController::actionDuplicate of the component ElementsController. The manipulation of the argument deleteProvisionalDraft results in authorization bypass.
This vulnerability is known as CVE-2026-84797. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More