Behavior Injection in Craft CMS by Craft
CVE-2026-86730
8.7HIGH
What is CVE-2026-86730?
Craft CMS versions prior to 5.10.12 are susceptible to a vulnerability that allows authenticated control-panel users to inject malicious behavior attachments into the system. By posting JSON strings as field-layout tab elements, users can circumvent the cleansing validations, leading to unauthorized code execution via Craft::createObject(). This flaw poses significant risks as it enables attackers to manipulate application behavior through injected code.
Affected Version(s)
cms 5.0.0-RC1 < 5.10.12
cms 5.10.12
