216.73.216.197

CVE-2026-44011

· Published 12/05/2026 21:16 · Modified 13/05/2026 16:16

Labels: CVE-2026-44011 2026-05-12CVE-2026-44011CWE-479[email protected]

Essential information

Published
12/05/2026 21:16
Modified
13/05/2026 16:16
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an input-handling flaw in a Yii object creation path that let any authenticated user inject malicious configuration and execute arbitrary commands on the server. The request-controlled condition field layouts data is converted into a live FieldLayout object without a Component::cleanseConfig() boundary. Because Craft configures models before parent::__construct(), attacker-controlled special config keys can take effect during object creation, and FieldLayout initialization then triggers a same-request event. This vulnerability is fixed in 4.17.12 and 5.9.18.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
craft / craft cms cpe:2.3:a:craft:craft_cms:4.0.0-4.17.12:*:*:*:*:*:*:*
craft / craft cms cpe:2.3:a:craft:craft_cms:5.9.18:*:*:*:*:*:*:*

References