Authenticated Remote Code Execution in Craft CMS Control Panel
CVE-2026-105985
What is CVE-2026-105985?
Craft CMS 5.10.13.2 features a significant vulnerability within its Control Panel that allows authenticated users to exploit component classes and property overrides. This vulnerability enables attackers to manipulate an EntryType object's parameters, such as uiLabelFormat, which can lead to the execution of arbitrary code through Twig templates. The compromised render path permits access to PHP functions, including system capabilities, effectively allowing the execution of operating-system commands with the associated privileges of the PHP/web-server process. Reproduced in instances without entry-editing or administrative permissions, this vulnerability underscores the necessity of stringent controls on user access and template rendering mechanisms.
Affected Version(s)
cms 5.0.0 < 5.11.0
