Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior/event configuration keys to be interpreted after decoding, enabling command execution as the PHP/web user. | |
| Title | Authenticated RCE via `condition.config` JSON cleanse bypass | |
| First Time appeared |
Craftcms
Craftcms cms |
|
| Weaknesses | CWE-915 | |
| CPEs | cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Craftcms
Craftcms cms |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Hackrate
Published:
Updated: 2026-08-24T15:55:31.625Z
Reserved: 2026-08-24T15:07:04.075Z
Link: CVE-2026-78416
Updated: 2026-08-24T15:55:22.303Z
Status : Received
Published: 2026-08-24T16:17:24.250
Modified: 2026-08-24T16:17:24.250
Link: CVE-2026-78416
No data.
OpenCVE Enrichment
No data.