Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105985— Authenticated RCE via render-components Entry Type overrides

Quick assessment

Affected
craftcms cms
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Craft CMS 5.10.13.2 中存在一个位于控制面板动作 的身份验证远程代码执行漏洞。 任何具有基本控制面板访问权限的已认证用户,都可以提交由请求控制的组件类及属性覆盖。攻击者首先覆盖 对象的 属性,然后渲染一个解析为同一请求缓存条目类型的条目,即可导致由请求提供的任意 Twig 代码通过 函数被求值执行。 该渲染路径未启用沙箱隔离。因此,Twig 字符串可调用对象可以直接访问如 等 PHP 函数,从而导致以 PHP/Web 服务器进程权限执行操作系统命令。 该问题已在使用一个激活状态的非管理员 Craf

CVSS 8.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105985

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Authenticated RCE via render-components Entry Type overrides
Source: CVE Program / CVE List V5
Vulnerability Description
Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components. Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate(). This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process. The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1336
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
craftcms cms 5.0.0 ~ 5.11.0 -

II. Public POCs for CVE-2026-105985

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105985

请登录查看更多情报信息。

Vendor Pages for CVE-2026-105985 (1)

Other References for CVE-2026-105985 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-105985

No comments yet


Leave a comment