CVE-2026-105985

Published: Ott 06, 2026 Last Modified: Ott 06, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,7
Source: 7004884b-51e2-48e8-b4a2-5ca29e80453e
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH 8,8
Source: 7004884b-51e2-48e8-b4a2-5ca29e80453e
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components.

Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate().

This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process.

The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required.

1336

Improper Neutralization of Special Elements Used in a Template Engine

Incomplete
Common Consequences
Security Scopes Affected:
Integrity
Potential Impacts:
Execute Unauthorized Code Or Commands
Applicable Platforms
Languages: Java, PHP, Python, JavaScript, Interpreted
Technologies: Not Technology-Specific, AI/ML, Client Server
View CWE Details
https://github.com/craftcms/cms
https://github.com/craftcms/cms/releases/tag/5.11.0
https://github.com/craftcms/cms/security/advisories/GHSA-g48f-wc2q-4rrv
https://www.hckrt.com/hacktivity/HCKRT-PVWH7W