CVE-2026-86732
Deferred Deferred - Pending Action

Remote Code Execution in Craft CMS via PHP Gadget Chain

Vulnerability report for CVE-2026-86732, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious class via criteria[withTransforms][0][class] that reaches ImageTransforms::normalizeTransform(), then use a PHP gadget chain with yii\rbac\PhpManager to execute code by pointing itemFile to a request log containing PHP payload in the User-Agent header.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
craftcms craft_cms to 5.10.12 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Craft CMS versions before 5.10.12 have a remote code execution flaw in the element-index endpoint. Authenticated content editors can exploit the criteria parameter to instantiate arbitrary classes. By injecting a malicious class via criteria[withTransforms][0][class], attackers can trigger ImageTransforms::normalizeTransform() and use a PHP gadget chain with yii\rbac\PhpManager to execute code. This involves pointing itemFile to a request log containing a PHP payload in the User-Agent header.

Detection Guidance

Check Craft CMS versions before 5.10.12 for the vulnerability. Inspect logs for suspicious class instantiation attempts via the element-index endpoint, particularly with criteria[withTransforms][0][class] parameter. Monitor for PHP payloads in User-Agent headers within request logs.

Impact Analysis

If you use Craft CMS versions before 5.10.12, an attacker with authenticated access as a content editor could execute arbitrary code on your server. This could lead to full system compromise, data theft, or unauthorized modifications to your website or backend systems.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR's data protection requirements and HIPAA's security rules. Non-compliance may result in legal penalties, fines, and reputational damage due to compromised sensitive data.

Mitigation Strategies

Upgrade Craft CMS to version 5.10.12 or later immediately. Restrict access to the element-index endpoint to trusted users only. Review and sanitize user-agent headers in logs to prevent PHP payload injection.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86732. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart