Remote Code Execution Vulnerability in Craft CMS by Craft
CVE-2026-86732

8.7HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-86732?

Craft CMS versions prior to 5.10.12 are susceptible to a remote code execution flaw in the element-index endpoint. This security weakness allows authenticated content editors to manipulate the criteria parameter to instantiate arbitrary classes. By injecting a malicious class through the criteria[withTransforms][0][class], attackers can reach the ImageTransforms::normalizeTransform() method. Utilizing a crafted PHP gadget chain, they can execute arbitrary code by directing an itemFile to a request log containing a PHP payload embedded in the User-Agent header, leading to potential unauthorized access and control over the server.

Affected Version(s)

cms 5.0.0-RC1 < 5.10.12

cms 5.10.12

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Haruna38
.