Craft CMS versions before 5.10.11 contain a critical authentication bypass vulnerability where the admin flag is not properly validated during user registration. This allows the admin flag to persist from deactivated admin accounts. An attacker can exploit this by registering a new account using the email address of a deactivated administrator, thereby inheriting full administrator privileges. The attack is viable when the target CMS instance has public user registration enabled and email verification disabled. This represents a significant access control flaw that could lead to complete site compromise. The vulnerability has been assigned CVE-2026-84795 and is documented in the GitHub security advisory GHSA-242m-9wq7-vhwq. A patch is available in Craft CMS version 5.10.11 and later.