CVE-2026-86730: Craft CMS CMS
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON strings to bypass cleanse validation, then trigger arbitrary object instantiation and code execution through Craft::createObject().
Affected products
- Craft CMS CMS: from 5.0.0-RC1, before 5.10.12 (fixed in 5.10.12)
Published 2026-09-08. Last modified 2026-09-08.