Input Handling Flaw in Craft CMS Leads to Potential Command Injection
CVE-2026-44011

8.6HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-44011?

Craft CMS contains an input-handling flaw that allows authenticated users to manipulate configuration settings and execute arbitrary commands on the server. This vulnerability arises from a flaw in the Yii object creation path, where request-controlled condition fields are incorrectly handled. Due to a lack of proper boundaries during the object creation process, attackers can exploit special configuration keys, leading to unauthorized execution of commands. This issue affects Craft CMS versions 4.0.0 to before 4.17.12 and 5.9.18, and has been resolved in subsequent updates.

Affected Version(s)

cms >= 4.0.0, < 4.17.12 < 4.0.0, 4.17.12

cms >= 5.0.0, < 5.9.18 < 5.0.0, 5.9.18

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.