Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can query these relations to read usernames, email addresses, and full names of any content author or uploader including administrators.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 02 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can query these relations to read usernames, email addresses, and full names of any content author or uploader including administrators. | |
| Title | Craft CMS before 5.11.0 PII Disclosure via GraphQL User Relations | |
| First Time appeared |
Craftcms
Craftcms craft Cms |
|
| Weaknesses | CWE-285 | |
| CPEs | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Craftcms
Craftcms craft Cms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-02T11:11:14.295Z
Reserved: 2026-09-02T10:19:06.331Z
Link: CVE-2026-84799
No data.
Status : Deferred
Published: 2026-09-02T12:17:16.637
Modified: 2026-09-02T13:54:48.797
Link: CVE-2026-84799
No data.
OpenCVE Enrichment
Updated: 2026-09-02T13:30:05Z
Weaknesses