Craft CMS before 5.10.12 Remote Code Execution via element-index
CVE-2026-86732

8.7HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-86732?

Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious class via criteria[withTransforms][0][class] that reaches ImageTransforms::normalizeTransform(), then use a PHP gadget chain with yii\rbac\PhpManager to execute code by pointing itemFile to a request log containing PHP payload in the User-Agent header.

Affected Version(s)

cms 5.0.0-RC1 < 5.10.12

cms 5.10.12

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Haruna38
.