CVE-2026-86731 | Craft CMS up to 5.10.11 UsersController users/activate-user actionActivateUser privileges management
A vulnerability was found in Craft CMS up to 5.10.11. It has been declared as problematic. Impacted is the function UsersController::actionActivateUser of the file users/activate-user of the component UsersController. The manipulation results in improper privilege management.
This vulnerability was named CVE-2026-86731. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More