Craft Cms · Craft Cms · CVE-2026-78416
**Name of the Vulnerable Software and Affected Versions**
Craft CMS versions 4.0.0-RC1 through 4.18.1
Craft CMS versions 5.0.0-RC1 through 5.10.5
**Description**
An authenticated remote code execution issue exists in the control panel element-search condition handling. A JSON cleanse bypass in `condition.config` allows Yii behavior or event configuration keys to be interpreted after decoding, which enables command execution as the PHP/web user.
**Recommendations**
Update Craft CMS to version 4.18.2 or later.
Update Craft CMS to version 5.10.6 or later.