Authenticated SQL Injection via nested eager-loading criteria
Report #HCKRT-B5BSMM in Craft CMS Vulnerability Disclosure Program
Disclosed Report
StatusClosed
TargetTier 1
Severity
Details
- Program
- Craft CMS Vulnerability Disclosure Program
- Target
- craftcms/cms
- Creation Date
- 7/26/2026 1:41:22 PM
- Severity
- High
- CVSS Score
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
- CVE Number
- CVE-2026-79991
- Affected versions
- >= 5.0.0, < 5.10.13
- Visibility
- Disclosed
- Disclosed at
- 9/1/2026 9:54:19 PM
- Author
- @Uncle_cui233
- Status
- Resolved (Closed)
- Vulnerability Type (CAPEC™)
- Blind SQL Injection
- Weakness (CWE)
- (CWE-89) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Summary
Authenticated SQL Injection via nested eager-loading criteria
Description
A non-admin, low-privileged Control Panel user (whose permission set is limited to the single baseline permission accessCp) can perform blind SQL injection against the element-index endpoint (element-indexes/get-elements and siblings), gaining arbitrary read access to the database.
This breaks Craft’s own privilege-separation model: a confined “editor/author” account (which is normally restricted to a handful of sections/fields) escalates to full database read access, which in practice is equivalent to admin-level information disclosure and serves as a stepping stone to full account takeover.
Precondition: Craft 5.10.12, Team or Pro edition (multi-user support), at least one existing non-admin account with the baseline accessCp permission, and at least one entry with an author. No non-default configuration is required.
Impact
This vulnerability allows any low-privileged authenticated Control Panel user to read the application database via blind SQL injection.
Timeline
Hackrate
Our platform helps companies to identify software vulnerabilities in a cost-efficient way. It provides a secure and centralized view of ethical hacking projects for your company.
US Patent Applied for HackGATE #63/645,845
Products
From the Blog
-
Hackrate Ranked 1st in Hungary and 22nd Globally at Hack The Box’s Global Cyber Skills Benchmark 2026
May 29 • 13 min read
-
Press release: Hackrate becomes Hungary’s first CVE Numbering Authority
Jan 13 • 5 min read ★
-
Let 2026 be the year bug bounty becomes part of how you build and operate
Jan 05 • 4 min read