Authenticated SQL Injection via nested eager-loading criteria


Report #HCKRT-B5BSMM in Craft CMS Vulnerability Disclosure Program

Disclosed Report
StatusClosed
Resolved
TargetTier 1
craftcms/cms
Severity
High
Details
Program
Craft CMS Vulnerability Disclosure Program
Target
craftcms/cms
Creation Date
7/26/2026 1:41:22 PM
Severity
High
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
CVE Number
CVE-2026-79991
Affected versions
>= 5.0.0, < 5.10.13
Visibility
Disclosed
Disclosed at
9/1/2026 9:54:19 PM
Author
@Uncle_cui233
Status
Resolved (Closed)
Vulnerability Type (CAPEC™)
Blind SQL Injection
Weakness (CWE)
(CWE-89) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Summary

Authenticated SQL Injection via nested eager-loading criteria

Description

A non-admin, low-privileged Control Panel user (whose permission set is limited to the single baseline permission accessCp) can perform blind SQL injection against the element-index endpoint (element-indexes/get-elements and siblings), gaining arbitrary read access to the database.

This breaks Craft’s own privilege-separation model: a confined “editor/author” account (which is normally restricted to a handful of sections/fields) escalates to full database read access, which in practice is equivalent to admin-level information disclosure and serves as a stepping stone to full account takeover.

Precondition: Craft 5.10.12, Team or Pro edition (multi-user support), at least one existing non-admin account with the baseline accessCp permission, and at least one entry with an author. No non-default configuration is required.

Impact

This vulnerability allows any low-privileged authenticated Control Panel user to read the application database via blind SQL injection.

Timeline

Reporter

Created.

Sunday, July 26, 2026 1:41 PM
Tyrell

Changed to Accepted (Open)

Wednesday, July 29, 2026 3:09 PM
brandonkelly

Changed to Resolved (Closed).Hi! The remediation was deployed, if you can bypass the fix, please let us know.

Friday, July 31, 2026 11:58 PM
brandonkelly

Github Security Advisory has been created. GHSA-4mgp-5vf2-7c9m

Friday, July 31, 2026 11:59 PM
Hackrate

Our platform helps companies to identify software vulnerabilities in a cost-efficient way. It provides a secure and centralized view of ethical hacking projects for your company.

US Patent Applied for HackGATE #63/645,845

Checking service status...

Hackrate Ethical Hacking Platform |
2026 ©

CVE Program Numbering Authority