Sceawere
Vulnerability Detail
CVE-2026-105985UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Craft CMS Authenticated RCE Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 14h ago
- Vendor
- craftcms
- Product
- cms
- Attack Type
- CWE-1336 Improper neutralization of special elements used in a template engine
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components. Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate(). This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process. The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-06T11:17:16.857Z",
"pubdate": "2026-10-06T11:17:16.857Z",
"executiveSummary": "An authenticated remote code execution (RCE) vulnerability exists in Craft CMS version 5.10.13.2 within the 'app/render-components' Control Panel action.\nThis vulnerability allows an attacker with basic, low-privileged Control Panel access to execute arbitrary system-level commands on the underlying web server.\nThe flaw stems from insufficient input validation and insecure deserialization of component classes and property overrides during the rendering process.\nBy manipulating the 'uiLabelFormat' property of an 'EntryType' object and leveraging the 'renderObjectTemplate()' function, an attacker can trigger the execution of unsandboxed Twig templates.\nBecause the template rendering engine is not properly restricted, attackers can invoke sensitive PHP functions, such as 'system()', to achieve remote code execution.\nExploitation is possible for any authenticated user, regardless of administrative privileges or specific optional permissions. This poses a critical risk to the confidentiality, integrity, and availability of the affected system, as an attacker can compromise the server environment, access sensitive data, or establish persistence.",
"technicalDetails": "The vulnerability resides in the 'app/render-components' action of the Craft CMS Control Panel. The root cause is the improper handling of request-controlled component classes and property overrides, which are passed into the application without adequate validation or sanitization.\nThe attack vector involves a two-stage process. First, an attacker utilizes the authenticated access to override the 'uiLabelFormat' property of an 'EntryType' object. This manipulated property is then cached by the application's request-caching mechanism.\nSecond, the attacker triggers the rendering of an Entry that resolves this specific, poisoned 'EntryType' object. During the rendering process, the application calls 'renderObjectTemplate()', which interprets the attacker-supplied Twig string. Because 'renderObjectTemplate()' does not enforce a sandbox environment, the Twig template has access to PHP's global function namespace.\nThe attacker can inject a malicious payload into the 'uiLabelFormat' string, such as a Twig construct designed to execute PHP system calls. For example, a payload leveraging Twig callable syntax can invoke 'system()', 'exec()', or 'passthru()' to execute arbitrary shell commands with the identity and privileges of the web-server user (e.g., www-data).\nThe exploitation flow is as follows: 1) Authenticated attacker initiates a request to override 'EntryType' properties via 'app/render-components'. 2) The malicious 'uiLabelFormat' is stored in the internal request cache. 3) The attacker initiates a request that forces the application to resolve the cached 'EntryType'. 4) 'renderObjectTemplate()' evaluates the malicious Twig string. 5) Arbitrary commands are executed by the PHP process.\nThis vulnerability is particularly severe because it requires no high-level administrative permissions, such as project configuration access, filesystem management, or entry-editing capabilities. Any user with a basic login to the Control Panel can facilitate the attack. The post-exploitation impact includes full system compromise, remote command execution, and potential lateral movement within the hosting environment."
}