PT-2026-25804 · Craft Cms · Craft Cms

Q1Uf3Ng

·

Published

2026-02-09

·

Updated

2026-03-25

·

CVE-2026-32263

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Craft CMS versions 5.6.0 through 5.9.10
Description Craft CMS is a content management system (CMS). A flaw exists in the way settings are processed, specifically within the EntryTypesController.php file. The $settings array, derived from parse str, is directly passed to Craft::configure() without proper sanitization using Component::cleanseConfig(). This allows for the injection of Yii2 behavior and event handlers through keys prefixed with 'as' or 'on', mirroring a previously identified attack vector. Successful exploitation requires administrator permissions within the Craft control panel and the allowAdminChanges setting to be enabled. An attacker can leverage this to achieve Remote Code Execution (RCE) using the same gadget chain as the original advisory.
Recommendations Versions 5.6.0 through 5.9.10 should be updated to version 5.9.11.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-32263
GHSA-7JX7-3846-M7W7
GHSA-QX2Q-Q59V-WF3J

Affected Products

Craft Cms