CVE-2026-78416
Authenticated RCE via `condition.config` JSON cleanse bypass
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior/event configuration keys to be interpreted after decoding, enabling command execution as the PHP/web user.
| CWE | CWE-915 |
| Vendor | craftcms |
| Product | cms |
| Published | Aug 24, 2026 |
| Last Updated | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for craftcms cms
Be the first to know when new unknown vulnerabilities affecting craftcms cms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
craftcms / cms
4.0.0-RC1 < 4.18.2 5.0.0-RC1 < 5.10.6
References
Credits
๐ saladin Hackrate