A vulnerability described as problematic has been identified in craftcms Craft CMS. Affected is the function validateIp of the component GraphQL. The manipulation results in server-side request forgery.

This vulnerability is cataloged as CVE-2026-72784. The attack may be launched remotely. There is no exploit available.