OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-105985

HIGH · CVSS 8.8 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Craft CMS 5.10.13.2 is vulnerable to an authenticated remote code execution flaw that allows any user with basic Control Panel access to execute arbitrary PHP commands through manipulated Twig templates. This vulnerability can lead to severe impacts, including full system command execution under the web server's privileges, making it critical for organizations using this version of Craft CMS to prioritize immediate patching. All users with access to the Control Panel should be alerted to this risk, especially those managing web applications that rely on Craft CMS.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105985
Severity
HIGH
CVSS
8.8
EPSS
N/A
Kubernetes

Original NVD Description

Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components. Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate(). This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process. The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required.