LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-72778

Published
CVSS8.8
Severityhigh
WeaknessCWE-915
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. Craft cleanses the outer request-controlled condition array via Component::cleanseConfig(), but Conditions::createCondition() later decodes and merges the JSON string in condition.config without re-running cleanseConfig() on the decoded configuration. Because condition.config is a JSON string during the first cleanse, Yii special config keys such as 'as ...' and 'on ...' can be hidden inside it and, after JSON decoding, are interpreted by Yii as behavior/event configuration during FieldLayout obje

References

← Back to the CVE Tracker

Our coverage of CVE-2026-72778

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-72778.