CVE-2026-72778
8.8Craft CMS · CMS
Craft CMS is vulnerable to remote code execution due to improper control of dynamically determined object attributes during configuration processing.
Executive summary
An authenticated remote code execution vulnerability in Craft CMS allows attackers to manipulate object attributes and compromise the application.
Vulnerability
This issue is caused by improper control of dynamically determined object attributes (CWE-915). An authenticated attacker can leverage this flaw to modify application configurations and achieve arbitrary code execution.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high risk of total system compromise. Exploitation enables an attacker to execute arbitrary commands, potentially leading to data exfiltration, unauthorized modification of site content, and complete loss of server control.
Remediation
Immediate Action: Update Craft CMS to version 5.10.6 or 4.18.2 to resolve the configuration injection flaw.
Proactive Monitoring: Review application configuration change logs and monitor for unexpected administrative actions that could indicate an attempt to exploit object attributes.
Compensating Controls: Utilize a Web Application Firewall to block suspicious requests containing unexpected object attribute modifications or configuration parameters.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability represents a significant security risk for Craft CMS installations. Administrators should perform an immediate update to the patched versions provided by the vendor to eliminate the potential for remote code execution.