Junglewise Threat Intelligence

CVE-2026-44011: Craft CMS authenticated remote code execution in FieldLayout

CVE-2026-44011 · Severity: high · CVSS 4 · Published 2026-05-12

Technologies: Craft CMS. Vendors: Craft CMS.

Executive brief

Craft CMS is a content management system used to build and manage websites. A security flaw allows an authorized user to inject malicious settings into the system's configuration. This can lead to remote code execution, allowing an attacker to take full control of the server, access sensitive data, or disrupt operations.

Technical details

Craft CMS contains a vulnerability in the Yii object creation path where request-controlled condition field layout data is converted into a FieldLayout object without proper cleansing via Component::cleanseConfig(). Because Craft configures models before the parent constructor is called, an attacker can inject special configuration keys that take effect during object creation. Specifically, an authenticated attacker can issue a crafted POST request to endpoints like /admin/actions/element-search/search to attach a malicious behavior (e.g., yii\behaviors\AttributeTypecastBehavior) and trigger a same-request event that executes arbitrary system commands. This is a variant of behavior-injection vulnerabilities and is fixed in versions 4.17.12 and 5.9.18.

Affected products

  • Craft CMS Craft CMS 4.0.0 to 4.17.11, 5.0.0 to 5.9.17

Timeline

  • 2026-04-27: advisory: Vendor advisory GHSA-qrgm-p9w5-rrfw published
  • 2026-05-12: disclosed: CVE-2026-44011 published
  • 2026-05-12: patched: Fixes released in versions 4.17.12 and 5.9.18

References