The Journal

Craft CMS 5.11: Login Fixes, a GraphQL Change, and a Round of Security Patches

Craft CMS 5.11 repairs passkey and two-factor logins, tightens up who can query user data over the API, and patches eleven security advisories. Here's what we reckon site owners need to know.

Andrew Fairlie
Written by
Andrew Fairlie
Technical Director · 13+ years with Craft CMS
Craft CMS Published 2 Sept 2026 3 min read

Craft CMS 5.11.0 was released on 1 September 2026. To be honest, it's a maintenance release. It has fixes, a security round, and some tidying up but there's no shiny new features here for editors.

We're updating the sites we look after as part of our normal maintenance cycle.

A (potential) breaking change with GraphQL

Craft has tightened up its GraphQL API. Queries that return user information (authors, uploaders, and similar) are now blocked unless the API schema explicitly has "Query for users" enabled.

If your Craft site only powers its own front end, this changes nothing for you. If Craft is feeding content to something else (like a Next.js frontend) author names will stop coming through until the schema is updated, and it might stop future site builds or cause errors.

We're checking for this on each site as we work through the updates, so if it applies to you it'll be handled at the same time.

Security fixes

This release patches eleven security advisories: four high-severity remote code execution flaws, an authorisation bypass, an account hijack route, four information disclosure issues, and one further low-severity code execution flaw.

That sounds like a lot written down but security rounds of this size are fairly routine for a CMS of Craft's size and maturity. The fact things are being found and fixed is a good thing!

Craft's own guidance is to update within 30 days for high-severity issues. Our maintenance cadence already sits inside that, so this release is being picked up in the normal way rather than as anything particularly urgent.

Other fixes

  • Passkeys work again. Anyone who set up a passkey before Craft 5.10 might have found it stopped logging them in.
  • Two-factor login is less fiddly. Password managers could submit the 2FA code form before the page was ready, bouncing you back to the login screen.
  • The control panel no longer freezes after closing a slide-out panel,
  • Alt text behaves properly on multi-site setups. Filling in alt text for the first time no longer copies it to every site in the install.
  • Multi-site content fixes, mostly around content being copied to a newly added site: the right version now wins, and URLs generate correctly.
  • Faster queues on sites processing lots of large background jobs (very helpful for a few of our sites!)

If you're running Craft 5 and not on a maintenance plan with us, it's worth scheduling. If you're on a version of Craft that's no longer supported, see "Do I need to upgrade from Craft 4?". As it turns out, Craft 4 also got an out-of-support update today, but that's just Craft CMS being class-acts rather than a sound strategy to rely on!

As always, feel free to reach out to me andrew.fairlie@mutual.agency with any questions!

Sources

Andrew Fairlie
Andrew Fairlie
Technical Director · 13+ years with Craft CMS

Andrew is Technical Director at Mutual, a Craft CMS Partner agency. He has been building with Craft CMS since its public beta in 2012 — working through every major version from Craft 1 to Craft 5 — and has delivered over 100 sites for clients including Apple, Transparency International, and Arts University Bournemouth.

He writes about Craft CMS on the Mutual blog and has contributed to net Magazine. At Mutual, he leads development of Mutual One, a marketing platform built on Craft CMS as its foundation.

He has spoken about Craft CMS to undergraduate students at the University of Brighton and Canterbury Christ Church University, and appeared on the Devmode.fm podcast. He has also trained other developers on working with the platform.

More from The Journal