CVE-2026-78416

Summary

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior/event configuration keys to be interpreted after decoding, enabling command execution as the PHP/web user.

Affected Software

VendorProductVersion RangeStatus
craftcmscms4.0.0-RC1 < 4.18.2affected
craftcmscms5.0.0-RC1 < 5.10.6affected

Weaknesses

  • CWE-915: CWE-915 Improperly controlled modification of Dynamically-Determined object attributes

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References