Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-105985: Craft CMS allows logged-in users to run server commands

CVE-2026-105985 · published 4 days ago
Summary

If someone can log into the Craft CMS control panel, they can send specially crafted requests that cause the system to execute any command on the web server. This happens because the software runs user‑provided code without proper restrictions. To protect yourself, update to the latest version of Craft CMS as soon as possible and limit control‑panel access to trusted users only.

What to do
  • Update craftcms cms to version 5.11.0 or later.
Affected software
VendorProductAffected versions
craftcms cms < 5.11.0
Original advisory text
Authenticated RCE via render-components Entry Type overrides
Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components.



Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate().



This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process.



The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.7 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-1336Improper Neutralization of Special Elements Used in a Template Engine
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-105985 · MITRE
Track software like this
Free during beta