Authenticated RCE via render-components Entry Type overrides


Report #HCKRT-PVWH7W in Craft CMS Vulnerability Disclosure Program

Disclosed Report
StatusClosed
Resolved
TargetTier 1
craftcms/cms
Severity
High
Details
Program
Craft CMS Vulnerability Disclosure Program
Target
craftcms/cms
Creation Date
8/13/2026 8:53:34 AM
Severity
High
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE Number
CVE-2026-105985
Affected versions
>= 5.0.0, < 5.11.0
Visibility
Disclosed
Disclosed at
10/6/2026 10:10:02 AM
Author
@allblue
Status
Resolved (Closed)
Vulnerability Type (CAPEC™)
Code Injection
Weakness (CWE)
(CWE-94) Improper Control of Generation of Code ('Code Injection')
Summary

Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components.

Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate().

This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process.

The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required.

Description

Prerequisites

  • Give the user Control Panel access.
  • Ensure at least one entry type and one entry exist. They do not need to correspond because typeId is overridden in memory.
  • Sign in as the limited user and record:
    • the authenticated session/Cookie header;
    • the raw csrfTokenValue returned by Craft for that session;
    • the numeric ID of an existing entry type;
    • the numeric element ID of an existing entry.
Impact

This is an authenticated OS command execution vulnerability. A malicious or compromised low-privileged Control Panel account can cross from application-level access to code execution as the PHP/web-server service account.

Depending on that operating-system account’s permissions, exploitation may allow the attacker to:

  • read Craft security keys, database credentials, and environment configuration available to PHP;
  • read or modify site content and user data;
  • modify application files writable by the web-server account and establish persistence;
  • access internal services reachable from the Craft host; or
  • disrupt availability.

The exploit does not require allowAdminChanges, project-config modification, Kubernetes object access, environment-variable control, prior filesystem access, root privileges, poison injection from another system, or exploitation of an upstream dependency vulnerability.

Timeline

Reporter

Created.

Thursday, August 13, 2026 8:53 AM
brandonkelly

Changed to Accepted (Open)

Tuesday, August 25, 2026 7:17 PM
brandonkelly

Changed to Resolved (Closed).Hi! The remediation was deployed, if you can bypass the fix, please let us know.

Tuesday, August 25, 2026 7:17 PM
brandonkelly

Github Security Advisory has been created. GHSA-g48f-wc2q-4rrv

Tuesday, August 25, 2026 7:18 PM
Hackrate

Our platform helps companies to identify software vulnerabilities in a cost-efficient way. It provides a secure and centralized view of ethical hacking projects for your company.

US Patent Applied for HackGATE #63/645,845

Checking service status...

Hackrate Ethical Hacking Platform |
2026 ©

CVE Program Numbering Authority