Home

Description

Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element resolver (src/gql/resolvers/elements/Address.php) performs no schema scope filtering on top-level queries. A GraphQL API token scoped to a single low-privilege user group can read every address in the system, including addresses belonging to users in groups the token has no authorization to access. This exposes PII, including full names, addresses, organizations, tax IDs, etc. This vulnerability is fixed in 4.17.12 and 5.9.18.

PUBLISHED Reserved 2026-05-04 | Published 2026-05-12 | Updated 2026-05-13 | Assigner GitHub_M




HIGH: 7.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-862: Missing Authorization

Product status

>= 5.0.0, < 5.9.18
affected

>= 4.0.0, < 4.17.12
affected

References

github.com/...ms/cms/security/advisories/GHSA-gj2p-p9m4-c8gw exploit

github.com/...ms/cms/security/advisories/GHSA-gj2p-p9m4-c8gw

github.com/...ommit/834b2cf61ad0dcee9b03add44ed402ebf18db128

cve.org (CVE-2026-44010)

nvd.nist.gov (CVE-2026-44010)

Download JSON