Remote Code Execution Vulnerability in Craft CMS by Craft
CVE-2026-86732
8.7HIGH
What is CVE-2026-86732?
Craft CMS versions prior to 5.10.12 are susceptible to a remote code execution flaw in the element-index endpoint. This security weakness allows authenticated content editors to manipulate the criteria parameter to instantiate arbitrary classes. By injecting a malicious class through the criteria[withTransforms][0][class], attackers can reach the ImageTransforms::normalizeTransform() method. Utilizing a crafted PHP gadget chain, they can execute arbitrary code by directing an itemFile to a request log containing a PHP payload embedded in the User-Agent header, leading to potential unauthorized access and control over the server.
Affected Version(s)
cms 5.0.0-RC1 < 5.10.12
cms 5.10.12
