Authenticated Remote Code Execution in Craft CMS by Craft
CVE-2026-78416

8.7HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
24 August 2026

What is CVE-2026-78416?

Craft CMS versions from 4.0.0-RC1 prior to 4.18.2 and from 5.0.0-RC1 prior to 5.10.6 exhibit a serious vulnerability impacting the control panel element-search condition handling. An exploitation of a JSON cleanse bypass in the condition.config allows Yii configuration keys to be misinterpreted once decoded. This flaw makes it possible for unauthorized commands to be executed as the PHP/web user, posing significant security risks for affected systems.

Affected Version(s)

cms 4.0.0-RC1 < 4.18.2

cms 5.0.0-RC1 < 5.10.6

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

saladin
Hackrate
.