Craft CMS versions before 5.10.11 contain a critical authentication bypass vulnerability where the admin flag is not properly validated during user registration. This flaw allows the admin flag to persist from deactivated admin accounts. An attacker can exploit this by registering a new account using a deactivated administrator's email address, thereby inheriting full administrator privileges. The attack is feasible when the target instance has public registration enabled and email verification disabled. This represents a significant privilege escalation risk for affected deployments. The vulnerability has been assigned CVE-2026-84795 and has been patched in version 5.10.11. Organizations using Craft CMS with public registration should prioritize upgrading immediately.