CVE-2026-84798 | Craft CMS up to 5.10.10 Elements Controller actionDeleteForSite privileges management
A vulnerability identified as problematic has been detected in Craft CMS up to 5.10.10. This vulnerability affects the function ElementsController::actionDeleteForSite of the component Elements Controller. This manipulation causes improper privilege management.
This vulnerability is handled as CVE-2026-84798. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More