PT-2026-80909 · Craft Cms · Craft Cms

·

CVE-2026-78416

·

Published

2026-08-24

·

Updated

2026-08-26

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Craft CMS versions 4.0.0-RC1 through 4.18.1 Craft CMS versions 5.0.0-RC1 through 5.10.5
Description An authenticated remote code execution issue exists in the control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior or event configuration keys to be interpreted after decoding, which enables command execution as the PHP/web user.
Recommendations Update Craft CMS to version 4.18.2 or later. Update Craft CMS to version 5.10.6 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78416

Affected Products

Craft Cms