Input Handling Flaw in Craft CMS Leads to Potential Command Injection
CVE-2026-44011
Key Information:
Badges
What is CVE-2026-44011?
Craft CMS contains an input-handling flaw that allows authenticated users to manipulate configuration settings and execute arbitrary commands on the server. This vulnerability arises from a flaw in the Yii object creation path, where request-controlled condition fields are incorrectly handled. Due to a lack of proper boundaries during the object creation process, attackers can exploit special configuration keys, leading to unauthorized execution of commands. This issue affects Craft CMS versions 4.0.0 to before 4.17.12 and 5.9.18, and has been resolved in subsequent updates.
Affected Version(s)
cms >= 4.0.0, < 4.17.12 < 4.0.0, 4.17.12
cms >= 5.0.0, < 5.9.18 < 5.0.0, 5.9.18
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
