CVE-2026-86730
Deferred Deferred - Pending Action

Authenticated Object Injection in Craft CMS via Field-Layout JSON Payloads

Vulnerability report for CVE-2026-86730, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: VulnCheck

Description

Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON strings to bypass cleanse validation, then trigger arbitrary object instantiation and code execution through Craft::createObject().

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
craftcms craft_cms to 5.10.12 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Craft CMS versions before 5.10.12 have a flaw where string-typed field-layout elements are not properly cleansed. Authenticated control-panel users can inject Yii2 behavior attachments and event handlers by sending field-layout tab elements as JSON strings. This bypasses cleanse validation and allows arbitrary object instantiation and code execution through Craft::createObject().

Detection Guidance

Check Craft CMS version with: composer show craftcms/craft. Inspect field-layout JSON inputs in control panel for suspicious Yii2 behavior attachments or event handlers. Monitor for unexpected object instantiation or code execution events.

Impact Analysis

An attacker with control-panel access could execute arbitrary code on the server, potentially leading to full system compromise, data theft, or further network infiltration. This could disrupt services or allow unauthorized access to sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection principles or HIPAA's security requirements. Organizations may face compliance breaches, legal penalties, or reputational damage if exploited.

Mitigation Strategies

Upgrade Craft CMS to version 5.10.12 or later immediately. Review and cleanse field-layout configurations. Restrict control-panel access to trusted users only. Monitor for unusual activity in logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86730. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart