CVE-2026-86732: Craft CMS CMS
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious class via criteria[withTransforms][0][class] that reaches ImageTransforms::normalizeTransform(), then use a PHP gadget chain with yii\rbac\PhpManager to execute code by pointing itemFile to a request log containing PHP payload in the User-Agent header.
Affected products
- Craft CMS CMS: from 5.0.0-RC1, before 5.10.12 (fixed in 5.10.12)
Published 2026-09-08. Last modified 2026-09-10.