Input Handling Flaw in Craft CMS Leads to Potential Command Injection
CVE-2026-44011
8.6HIGH
What is CVE-2026-44011?
Craft CMS contains an input-handling flaw that allows authenticated users to manipulate configuration settings and execute arbitrary commands on the server. This vulnerability arises from a flaw in the Yii object creation path, where request-controlled condition fields are incorrectly handled. Due to a lack of proper boundaries during the object creation process, attackers can exploit special configuration keys, leading to unauthorized execution of commands. This issue affects Craft CMS versions 4.0.0 to before 4.17.12 and 5.9.18, and has been resolved in subsequent updates.
Affected Version(s)
cms >= 4.0.0, < 4.17.12 < 4.0.0, 4.17.12
cms >= 5.0.0, < 5.9.18 < 5.0.0, 5.9.18
