🔐 CVE Alert

CVE-2026-105985

HIGH 8.8

Authenticated RCE via render-components Entry Type overrides

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components. Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate(). This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process. The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required.

CWE CWE-1336
Vendor craftcms
Product cms
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for craftcms cms

Be the first to know when new high vulnerabilities affecting craftcms cms are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

craftcms / cms
5.0.0 < 5.11.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
hckrt.com: https://www.hckrt.com/hacktivity/HCKRT-PVWH7W github.com: https://github.com/craftcms/cms/releases/tag/5.11.0 github.com: https://github.com/craftcms/cms github.com: https://github.com/craftcms/cms/security/advisories/GHSA-g48f-wc2q-4rrv

Credits

🔍 @allblue Hackrate