VYPR
High severity8.8NVD Advisory· Published Mar 11, 2026· Updated Jun 17, 2026

CVE-2026-31857

CVE-2026-31857

Description

Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The BaseElementSelectConditionRule::getElementIds() method passes user-controlled string input through renderObjectTemplate() -- an unsandboxed Twig rendering function with escaping disabled. Any authenticated Control Panel user (including non-admin roles such as Author or Editor) can achieve full RCE by sending a crafted condition rule via standard element listing endpoints. This vulnerability requires no admin privileges, no special permissions beyond basic control panel access, and bypasses all production hardening settings (allowAdminChanges: false, devMode: false, enableTwigSandbox: true). Users should update to the patched 5.9.9 or 4.17.4 release to mitigate the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
craftcms/cmsPackagist
>= 5.0.0-RC1, < 5.9.95.9.9
craftcms/cmsPackagist
>= 4.0.0-beta.1, < 4.17.44.17.4

Affected products

13
  • Craftcms/Craft CMS11 versions
    cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*+ 10 more
    • cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*range: >=4.0.0.1,<4.17.4
    • cpe:2.3:a:craftcms:craft_cms:4.0.0:-:*:*:*:*:*:*
    • cpe:2.3:a:craftcms:craft_cms:4.0.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:craftcms:craft_cms:4.0.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:craftcms:craft_cms:4.0.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:craftcms:craft_cms:4.0.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:craftcms:craft_cms:4.0.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:craftcms:craft_cms:4.0.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:craftcms:craft_cms:4.0.0:rc3:*:*:*:*:*:*
    • cpe:2.3:a:craftcms:craft_cms:5.0.0:-:*:*:*:*:*:*
    • cpe:2.3:a:craftcms:craft_cms:5.0.0:rc1:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 5.0.0-RC1, < 5.9.9
  • Range: >= 5.0.0-RC1, < 5.9.9

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.