PT-2026-25804 · Craft Cms · Craft Cms
Q1Uf3Ng
·
Published
2026-02-09
·
Updated
2026-03-25
·
CVE-2026-32263
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Craft CMS versions 5.6.0 through 5.9.10
Description
Craft CMS is a content management system (CMS). A flaw exists in the way settings are processed, specifically within the
EntryTypesController.php file. The $settings array, derived from parse str, is directly passed to Craft::configure() without proper sanitization using Component::cleanseConfig(). This allows for the injection of Yii2 behavior and event handlers through keys prefixed with 'as' or 'on', mirroring a previously identified attack vector. Successful exploitation requires administrator permissions within the Craft control panel and the allowAdminChanges setting to be enabled. An attacker can leverage this to achieve Remote Code Execution (RCE) using the same gadget chain as the original advisory.Recommendations
Versions 5.6.0 through 5.9.10 should be updated to version 5.9.11.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Craft Cms