Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schema’s allowed sites. The query path (ElementResolverprepareElementQuery) correctly calls prepareArguments()`, so queries to unauthorized sites return empty. But mutations bypass this entirely — an attacker with a token scoped to Site A can create, modify, or delete entries in Site B by passing siteId in the mutations argument. | |
| Title | Authenticated SQL Injection via nested eager-loading criteria | |
| First Time appeared |
Craftcms
Craftcms cms |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Craftcms
Craftcms cms |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Hackrate
Published:
Updated: 2026-09-02T17:55:14.034Z
Reserved: 2026-08-25T16:39:03.171Z
Link: CVE-2026-79991
No data.
Status : Received
Published: 2026-09-02T15:17:42.673
Modified: 2026-09-02T18:21:25.997
Link: CVE-2026-79991
No data.
OpenCVE Enrichment
No data.
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')