Skip to main content
Vulnerability Database/CVE-2026-105985

CVE-2026-105985: Craft CMS RCE Vulnerability

CVE-2026-105985 is an authenticated remote code execution vulnerability in Craft CMS 5.10.13.2 affecting users with basic Control Panel access. Attackers can exploit Twig template rendering to execute system commands. This article covers technical details, affected versions, exploitation risks, and mitigation strategies.

Published:

CVE-2026-105985 Overview

Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components. Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object's uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker causes attacker-supplied Twig to be evaluated by renderObjectTemplate(). The render path is not sandboxed, allowing a Twig string callable to reach PHP functions such as system(). The result is operating-system command execution with the privileges of the PHP or web-server process. The flaw is categorized as [CWE-1336] (Improper Neutralization of Special Elements Used in a Template Engine).

Critical Impact

A low-privileged Control Panel user with no optional permissions can achieve arbitrary OS command execution on the Craft CMS host.

Affected Products

  • Craft CMS 5.10.13.2
  • Craft CMS 5.x releases prior to 5.11.0
  • Craft Team edition deployments exposing the Control Panel to non-admin users

Discovery Timeline

  • 2026-10-06 - CVE-2026-105985 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-105985

Vulnerability Analysis

The vulnerability resides in the Control Panel app/render-components action. This endpoint accepts a component class name and a set of property overrides supplied by the HTTP request. Craft instantiates the requested component and applies the attacker-controlled properties directly to it.

An attacker first targets an EntryType object and overrides its uiLabelFormat property with a Twig payload. A subsequent request renders an Entry that resolves to the same entry type cached for the current request. When Craft generates the entry's UI label, it calls renderObjectTemplate() on the attacker-controlled uiLabelFormat value.

The renderObjectTemplate() path is not sandboxed. Twig string callables inside the payload can invoke PHP functions such as system(), exec(), or passthru(), giving the attacker command execution as the web-server user. The issue was reproduced with a non-admin Craft Team user that had no optional permissions enabled.

Root Cause

Two design flaws combine to enable the exploit. First, the render-components action trusts request-supplied property assignments on sensitive model objects without allow-listing writable properties. Second, the Twig environment used by renderObjectTemplate() is not sandboxed, so template strings can reach arbitrary PHP callables.

Attack Vector

Exploitation is remote and requires only a low-privileged authenticated Control Panel session. The attacker sends two crafted POST requests to app/render-components: one to poison the request-cached EntryType and a second to trigger rendering of an Entry whose label resolution evaluates the injected Twig. No access to entry editing, Settings, utilities, user management, project config, filesystem, Kubernetes, or environment variables is required. Full technical details are available in the Craft CMS Security Advisory GHSA-g48f-wc2q-4rrv and the HCKRT Hacktivity Report PVWH7W.

Detection Methods for CVE-2026-105985

Indicators of Compromise

  • POST requests to /index.php?p=admin/actions/app/render-components or /admin/actions/app/render-components that include request parameters setting uiLabelFormat or other model property overrides.
  • Twig syntax such as {{ ... }}, filter, or references to PHP functions like system, exec, passthru, or shell_exec appearing in Control Panel POST bodies.
  • php, php-fpm, or www-data processes spawning shells (sh, bash), curl, wget, or nc shortly after Control Panel activity.

Detection Strategies

  • Enable web-server access logging for the Craft Control Panel and alert on requests to the render-components action from non-admin accounts.
  • Correlate authenticated Control Panel sessions with child-process creation events on the Craft host to surface Twig-to-PHP command execution chains.
  • Deploy web application firewall rules that inspect render-components payloads for Twig template delimiters and PHP function names.

Monitoring Recommendations

  • Monitor outbound network connections from the PHP/web-server process to unexpected destinations, which often indicate post-exploitation egress.
  • Track creation of new PHP files, cron jobs, or scheduled tasks on the Craft CMS host, especially under web/ and writable storage directories.
  • Audit the Craft users table and session store for recently created low-privileged accounts that subsequently access the Control Panel.

How to Mitigate CVE-2026-105985

Immediate Actions Required

  • Upgrade Craft CMS to version 5.11.0 or later, which removes the unsafe property assignment path and restricts the render-components action.
  • Restrict Control Panel access at the network layer to trusted administrator IP ranges until patching is complete.
  • Review all Craft user accounts and remove or disable any unexpected low-privileged Control Panel users.
  • Rotate Craft security keys, database credentials, and any secrets reachable from the web-server process after patching.

Patch Information

The fix is published in Craft CMS 5.11.0. See the GitHub Security Advisory GHSA-g48f-wc2q-4rrv and the 5.11.0 release notes for the authoritative patch details. Source code is available in the Craft CMS repository.

Workarounds

  • Block external access to /admin/actions/app/render-components via reverse proxy or WAF rules until the upgrade is applied.
  • Enforce multi-factor authentication on all Control Panel accounts to reduce the risk of credential-based exploitation.
  • Run the Craft PHP process under a dedicated, least-privileged system user with no write access to code directories to limit post-exploitation impact.
bash
# Example nginx rule to block the vulnerable action until patched
location ~* /admin/actions/app/render-components {
    return 403;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.