CVE-2026-105985
Received Received - Intake

Authenticated RCE in Craft CMS via Twig Component Rendering

Vulnerability report for CVE-2026-105985, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: Hackrate

Description

Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components. Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate(). This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process. The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
craftcms cms 5.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1336 The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Craft CMS 5.10.13.2 has an authenticated remote code execution vulnerability in the Control Panel action app/render-components. An attacker with basic Control Panel access can submit malicious component classes and property overrides. By manipulating an EntryType object’s uiLabelFormat and rendering an Entry, arbitrary Twig code can be executed via renderObjectTemplate(). This Twig execution path is not sandboxed, allowing calls to PHP functions like system(), leading to OS command execution with the web server’s privileges.

Detection Guidance

Check Craft CMS logs for suspicious Control Panel actions or Twig template rendering requests. Monitor for unexpected system() calls in PHP execution traces. Inspect entry type uiLabelFormat overrides via database queries.

Impact Analysis

An attacker could gain full control over the server hosting Craft CMS by executing arbitrary operating system commands. This could lead to data theft, website defacement, or further network compromise. The attack requires only basic authenticated access, making it accessible even to low-privilege users.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR’s data protection principles and HIPAA’s security requirements. Organizations may face legal penalties, reputational damage, and loss of customer trust if exploited.

Mitigation Strategies

Upgrade Craft CMS to a patched version immediately. Restrict Control Panel access to trusted users only. Disable non-essential permissions for Craft Team users. Review and audit all uiLabelFormat customizations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105985. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart