AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-72778

HIGH · CVSS 8.8 EPSS 0.45% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Craft CMS versions prior to 4.18.2 and 5.10.6 are vulnerable to an authenticated remote code execution flaw due to improper handling of JSON-encoded configuration in the control panel's element-search conditions. This vulnerability allows an authenticated attacker with a valid CSRF token to execute arbitrary operating system commands with the privileges of the PHP/web user. Organizations using affected Craft CMS versions should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72778
Severity
HIGH
CVSS
8.8
EPSS
0.45%

Original NVD Description

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. Craft cleanses the outer request-controlled condition array via Component::cleanseConfig(), but Conditions::createCondition() later decodes and merges the JSON string in condition.config without re-running cleanseConfig() on the decoded configuration. Because condition.config is a JSON string during the first cleanse, Yii special config keys such as 'as ...' and 'on ...' can be hidden inside it and, after JSON decoding, are interpreted by Yii as behavior/event configuration during FieldLayout object creation. An attacker with an authenticated control panel session (and a valid CSRF token) can exploit this to execute operating system commands as the PHP/web user.