CVE-2026-78416

8.7

Craft CMS · CMS

Craft CMS contains a vulnerability involving improperly controlled modification of dynamically determined object attributes, which can be exploited by authenticated users to gain elevated privileges.

Executive summary

A high-severity attribute injection vulnerability in Craft CMS allows authenticated users to manipulate object properties, leading to total compromise of the application.

Vulnerability

The software fails to properly control the modification of object attributes (CWE-915). An authenticated attacker can exploit this to overwrite critical internal object states, resulting in unauthorized privilege escalation or system control.

Business impact

With a CVSS score of 8.7, this vulnerability poses a severe threat to the confidentiality, integrity, and availability of the content management system. Successful exploitation could allow an attacker to hijack administrative sessions or manipulate site content, leading to significant reputational damage and data breaches.

Remediation

Immediate Action: Update Craft CMS to version 4.18.2 or 5.10.6 depending on the active branch.

Proactive Monitoring: Monitor audit logs for suspicious administrative actions or unexpected changes to user roles and object configurations.

Compensating Controls: Restrict administrative access to the Craft CMS control panel to known, trusted IP addresses using network-level access control lists or VPNs.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability is a high-priority update for all Craft CMS deployments. Administrators should verify their current version against the provided ranges and apply the relevant security patches immediately to prevent potential attribute manipulation attacks.

More Craft CMS CVEs