Security
Loading…

CVE-2026-86730

HIGHCVSS 8.8
Description

Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON strings to bypass cleanse validation, then trigger arbitrary object instantiation and code execution through Craft::createObject().

Timeline
Published:September 8th, 2026 4:18 PM
Last modified:September 8th, 2026 7:53 PM
CVSS Scoring

CVSS v3: 8.8 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute