Executive brief
Craft CMS, a popular content management system, contains a vulnerability that allows an administrator to execute unauthorized commands on the server. By exploiting this flaw, a malicious user with administrative access can take full control of the website, steal sensitive database credentials, and access internal security keys. This could lead to a complete compromise of the site's data and underlying infrastructure.
Technical details
A remote code execution (RCE) vulnerability exists in Craft CMS within the `FieldsController::actionRenderCardPreview()` method. The root cause is the failure to call `Component::cleanseConfig()` before passing the `fieldLayoutConfig` POST parameter to `Fields::createLayout()`. An authenticated attacker with administrative privileges can exploit this by injecting Yii2 event handlers (such as 'on init') into the configuration array. When the object is instantiated, the injected event handler triggers, allowing for arbitrary PHP code execution and the disclosure of sensitive environment variables like `CRAFT_SECURITY_KEY`. The issue is resolved in version 5.9.14.
Affected products
- Craft CMS cms >= 5.5.0, <= 5.9.13
Timeline
- 2026-06-02: advisory: Original GHSA-86vw-x4ww-x467 published
- 2026-06-21: disclosed: CVE-2026-56382 published
- 2026-08-06: other: Duplicate advisory GHSA-pmm4-v8f6-4vpp withdrawn