Executive brief
Craft CMS, a popular web content management system, contains a flaw in its asset browser feature that allows authenticated content editors to execute arbitrary code on the server. An editor with the ability to view assets can inject malicious code through specially crafted requests, potentially compromising the entire CMS and any data it manages. This requires an editor account (not necessarily admin-level) with access to a volume containing at least one asset.</brief> <parameter name="technical_details">The vulnerability is a code injection flaw (CWE-94) affecting the element-index endpoint. The root cause is that the ImageTransforms::normalizeTransform() function, which accepts user-controlled criteria, was not adequately protected by a prior CVE-2025-32432 fix that only hardened one call site. An authenticated editor can supply a malicious criteria[withTransforms][0][class] parameter to instantiate arbitrary classes. By chaining this with the yii\rbac\PhpManager gadget, an attacker can point itemFile to a request log containing a PHP payload (injected via User-Agent header) and achieve remote code execution. The attack requires an authenticated session with contentEditor privileges and viewAssets access to a volume.
Affected products
- Craft CMS CMS 5.0.0-RC1 to before 5.10.12
Timeline
- 2026-08-25: disclosed: GitHub Security Advisory GHSA-9wcj-wqqh-cqvg published
- 2026-09-08: advisory: CVE-2026-86732 published on NVD
- 2026-08-25: patched: Version 5.10.12 patches the vulnerability