Intel

AIKIDO-2026-32002

craftcms/cms is vulnerable to Privilege Escalation

Privilege Escalation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Today

43

Medium Risk

This Affects:

PHPcraftcms/cms
3.1.0 - 5.10.11
Fixed in 5.10.12
Are you affected? Scan for Free

TL;DR

craftcms/cms lets control panel users holding administrateUsers activate other accounts. The activate-user action did not require the caller to be an admin when the target account is an admin. A non-admin with that permission could therefore activate admin accounts. The fix requires the caller to be an admin before activating an admin target.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you have granted the administrateUsers permission to non-admin control panel users.

Background info

craftcms/cms is vulnerable to Privilege Escalation in versions 3.1.0 - 5.10.11.

How to fix this

Upgrade the craftcms/cms library to the patch version.