Behavior Injection in Craft CMS by Craft
CVE-2026-86730

8.7HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-86730?

Craft CMS versions prior to 5.10.12 are susceptible to a vulnerability that allows authenticated control-panel users to inject malicious behavior attachments into the system. By posting JSON strings as field-layout tab elements, users can circumvent the cleansing validations, leading to unauthorized code execution via Craft::createObject(). This flaw poses significant risks as it enables attackers to manipulate application behavior through injected code.

Affected Version(s)

cms 5.0.0-RC1 < 5.10.12

cms 5.10.12

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.