CVE-2026-44010General

LOWCVSS 7.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element resolver (src/gql/resolvers/elements/Address.php) performs no schema scope filtering on top-level queries. A GraphQL API token scoped to a single low-privilege user group can read every address in the system, including addresses belonging to users in groups the token has no authorization to access. This exposes PII, including full names, addresses, organizations, tax IDs, etc. This vulnerability is fixed in 4.17.12 and 5.9.18.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-12); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-14: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-14: 105-1205-14
Signal classification2 categories
General
150.0%
PoC
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-121
General1
2026-05-141
PoC1
Full discourse2 posts
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #CraftCMS: disponibili #PoC per lo sfruttamento delle CVE-2026-44010 e CVE-2026-44011 Rischio: 🔴 Tipologia 🔸 Remote Code Execution 🔸 Information Disclosure 🔗 https://www.acn.gov.it/portale/en/w/craft-cms-disponibili-poc-per-lo-sfruttamento-delle-cve-2026-44010-e-cve-2026-44011 ⚠ Importante aggiornare i software interessati https://t.co/grmfBND2RE

    Post summary

    The tweet announces publicly available PoCs for CVE‑2026‑44010 and CVE‑2026‑44011, noting RCE and information disclosure risks, and urges users to update affected software.

    00000211
    611 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-44010 Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element resolver (src/gql/resolvers/elements/Address.php)… https://www.cve.org/CVERecord?id=CVE-2026-44010

    Post summary

    The text briefly announces CVE-2026-44010 for Craft CMS, listing affected versions but providing no deeper technical, exploitation, or mitigation details.

    00000131
    57.5K followersView on X

Explore more