Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Craftcms cms
|
|
| Vendors & Products |
Craftcms cms
|
Tue, 08 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON strings to bypass cleanse validation, then trigger arbitrary object instantiation and code execution through Craft::createObject(). | |
| Title | Craft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCE | |
| First Time appeared |
Craftcms
Craftcms craft Cms |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Craftcms
Craftcms craft Cms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-08T15:36:22.493Z
Reserved: 2026-09-08T11:31:09.013Z
Link: CVE-2026-86730
Updated: 2026-09-08T15:36:19.637Z
Status : Received
Published: 2026-09-08T16:18:34.667
Modified: 2026-09-08T16:18:34.667
Link: CVE-2026-86730
No data.
OpenCVE Enrichment
Updated: 2026-09-08T17:00:02Z
-
CWE-94
Improper Control of Generation of Code ('Code Injection')