Authenticated Remote Code Execution in Craft CMS by Craft
CVE-2026-78416
8.7HIGH
What is CVE-2026-78416?
Craft CMS versions from 4.0.0-RC1 prior to 4.18.2 and from 5.0.0-RC1 prior to 5.10.6 exhibit a serious vulnerability impacting the control panel element-search condition handling. An exploitation of a JSON cleanse bypass in the condition.config allows Yii configuration keys to be misinterpreted once decoded. This flaw makes it possible for unauthorized commands to be executed as the PHP/web user, posing significant security risks for affected systems.
Affected Version(s)
cms 4.0.0-RC1 < 4.18.2
cms 5.0.0-RC1 < 5.10.6
