Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Craftcms cms
|
|
| Vendors & Products |
Craftcms cms
|
Tue, 08 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious class via criteria[withTransforms][0][class] that reaches ImageTransforms::normalizeTransform(), then use a PHP gadget chain with yii\rbac\PhpManager to execute code by pointing itemFile to a request log containing PHP payload in the User-Agent header. | |
| Title | Craft CMS before 5.10.12 Remote Code Execution via element-index | |
| First Time appeared |
Craftcms
Craftcms craft Cms |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Craftcms
Craftcms craft Cms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-08T15:14:02.315Z
Reserved: 2026-09-08T11:31:09.013Z
Link: CVE-2026-86732
No data.
Status : Received
Published: 2026-09-08T16:18:35.333
Modified: 2026-09-08T16:18:35.333
Link: CVE-2026-86732
No data.
OpenCVE Enrichment
Updated: 2026-09-08T17:30:05Z