CVE-2026-84798 | Craft CMS up to 5.10.10 Elements Controller actionDeleteForSite privileges management

SecurityVulns

A vulnerability identified as problematic has been detected in Craft CMS up to 5.10.10. This vulnerability affects the function ElementsController::actionDeleteForSite of the component Elements Controller. This manipulation causes improper privilege management.

This vulnerability is handled as CVE-2026-84798. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More