Remote Code Execution Vulnerability in Craft CMS by Craft
CVE-2026-33157
8.6HIGH
What is CVE-2026-33157?
Craft CMS, a leading content management system, has a Remote Code Execution vulnerability affecting versions from 5.6.0 to prior to 5.9.13. This vulnerability allows any authenticated user with control panel access to exploit the system. It arises from a bypass of previous source code patches that added sanitization functions to prevent behavior/event injection. Notably, the fieldLayouts parameter in the ElementIndexesController remains unsanitized, enabling attackers to trigger unintended behavior injection through various methods. The issue has been addressed in the 5.9.13 release, ensuring greater security against such exploits.
Affected Version(s)
cms >= 5.6.0, < 5.9.13
