Input Handling Flaw in Craft CMS Leads to Potential Command Injection
CVE-2026-44011

8.6HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
12 May 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-44011?

Craft CMS contains an input-handling flaw that allows authenticated users to manipulate configuration settings and execute arbitrary commands on the server. This vulnerability arises from a flaw in the Yii object creation path, where request-controlled condition fields are incorrectly handled. Due to a lack of proper boundaries during the object creation process, attackers can exploit special configuration keys, leading to unauthorized execution of commands. This issue affects Craft CMS versions 4.0.0 to before 4.17.12 and 5.9.18, and has been resolved in subsequent updates.

Affected Version(s)

cms >= 4.0.0, < 4.17.12 < 4.0.0, 4.17.12

cms >= 5.0.0, < 5.9.18 < 5.0.0, 5.9.18

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.