Authenticated Remote Code Execution in Craft CMS Control Panel
CVE-2026-105985

8.7HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105985?

Craft CMS 5.10.13.2 features a significant vulnerability within its Control Panel that allows authenticated users to exploit component classes and property overrides. This vulnerability enables attackers to manipulate an EntryType object's parameters, such as uiLabelFormat, which can lead to the execution of arbitrary code through Twig templates. The compromised render path permits access to PHP functions, including system capabilities, effectively allowing the execution of operating-system commands with the associated privileges of the PHP/web-server process. Reproduced in instances without entry-editing or administrative permissions, this vulnerability underscores the necessity of stringent controls on user access and template rendering mechanisms.

Affected Version(s)

cms 5.0.0 < 5.11.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@allblue
Hackrate
.