Description
Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious class via criteria[withTransforms][0][class] that reaches ImageTransforms::normalizeTransform(), then use a PHP gadget chain with yii\rbac\PhpManager to execute code by pointing itemFile to a request log containing PHP payload in the User-Agent header.
Published: 2026-09-08
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Craft CMS versions before 5.10.12 expose a remote code execution flaw in the element-index endpoint. An authenticated content editor can provide a specially crafted "criteria" parameter that instructs the system to instantiate an arbitrary PHP class. The attack path uses the criteria[withTransforms][0][class] value, which is passed to ImageTransforms::normalizeTransform(), and then leverages a PHP gadget chain involving yii\rbac\PhpManager. By pointing the gadget’s itemFile to a request log containing malicious PHP code in the User-Agent header, the attacker can execute arbitrary PHP on the server.

Affected Systems

All installations of Craft CMS whose version is older than 5.10.12 are vulnerable. The affected product is the Craft CMS content management system released by Craft CMS and the vulnerability exists regardless of deployment environment, provided the element-index endpoint is reachable and a content editor account is available.

Risk and Exploitability

Based on the CVSS score of 8.7, the vulnerability is rated as high severity, meaning that exploitation grants an attacker the ability to run arbitrary PHP code on the affected server. The lack of an EPSS score means there is no published data on current exploitation probability, but the remote nature of the attack and the fact that it requires only an authenticated content‑editor account—an account that is common in many deployments—combined with the absence of a KEV listing, indicate that this flaw could be actively abused in the wild. Attackers would issue a network request to the element‑index endpoint supplying a crafted criteria parameter that forces the system to instantiate a user‑supplied PHP class, creating a complete gadget chain that ultimately executes code in the context of the web application. Because the code runs with the privileges of the web server, impact could range from data theft and defacement to full server compromise.

Generated by OpenCVE AI on September 8, 2026 at 17:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Craft CMS patch (5.10.12 or newer) to fix the element-index vulnerability.
  • Restrict the element-index endpoint so that only privileged administrators can access it, or disable it entirely via configuration if not needed.
  • Update the Yii PHP framework and PHP interpreter to versions that eliminate the vulnerable gadget chain, and review php.ini settings to prevent arbitrary code execution, such as disabling the modification of request headers or log file contents by user input.

Generated by OpenCVE AI on September 8, 2026 at 17:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Craftcms cms
Vendors & Products Craftcms cms

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious class via criteria[withTransforms][0][class] that reaches ImageTransforms::normalizeTransform(), then use a PHP gadget chain with yii\rbac\PhpManager to execute code by pointing itemFile to a request log containing PHP payload in the User-Agent header.
Title Craft CMS before 5.10.12 Remote Code Execution via element-index
First Time appeared Craftcms
Craftcms craft Cms
Weaknesses CWE-94
CPEs cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Vendors & Products Craftcms
Craftcms craft Cms
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T13:54:12.753Z

Reserved: 2026-09-08T11:31:09.013Z

Link: CVE-2026-86732

cve-icon Vulnrichment

Updated: 2026-09-10T13:54:08.751Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T16:18:35.333

Modified: 2026-09-10T14:17:09.963

Link: CVE-2026-86732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T17:30:05Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')