CVE-2026-92594 | Craft CMS up to 5.10.x GraphQL Resolver Gql::canQueryUsers improper authorization
A vulnerability marked as problematic has been reported in Craft CMS up to 5.10.x. This vulnerability affects the function Gql::canQueryUsers of the component GraphQL Resolver. The manipulation leads to improper authorization.
This vulnerability is uniquely identified as CVE-2026-92594. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More