VYPR
High severityNVD Advisory· Published Aug 24, 2026

CVE-2026-78416

CVE-2026-78416

Description

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior/event configuration keys to be interpreted after decoding, enabling command execution as the PHP/web user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Craftcms/CMSllm-fuzzy
    Range: 4.0.0-RC1 <= v < 4.18.2, 5.0.0-RC1 <= v < 5.10.6
  • Range: 4.0.0-RC1 <= v < 4.18.2, 5.0.0-RC1 <= v < 5.10.6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.