Authenticated RCE via render-components Entry Type overrides
Report #HCKRT-PVWH7W in Craft CMS Vulnerability Disclosure Program
Disclosed Report
StatusClosed
TargetTier 1
Severity
Details
- Program
- Craft CMS Vulnerability Disclosure Program
- Target
- craftcms/cms
- Creation Date
- 8/13/2026 8:53:34 AM
- Severity
- High
- CVSS Score
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CVE Number
- CVE-2026-105985
- Affected versions
- >= 5.0.0, < 5.11.0
- Visibility
- Disclosed
- Disclosed at
- 10/6/2026 10:10:02 AM
- Author
- @allblue
- Status
- Resolved (Closed)
- Vulnerability Type (CAPEC™)
- Code Injection
- Weakness (CWE)
- (CWE-94) Improper Control of Generation of Code ('Code Injection')
Summary
Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components.
Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate().
This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process.
The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required.
Description
Prerequisites
- Give the user Control Panel access.
- Ensure at least one entry type and one entry exist. They do not need to correspond because typeId is overridden in memory.
- Sign in as the limited user and record:
- the authenticated session/Cookie header;
- the raw
csrfTokenValuereturned by Craft for that session; - the numeric ID of an existing entry type;
- the numeric element ID of an existing entry.
Impact
This is an authenticated OS command execution vulnerability. A malicious or compromised low-privileged Control Panel account can cross from application-level access to code execution as the PHP/web-server service account.
Depending on that operating-system account’s permissions, exploitation may allow the attacker to:
- read Craft security keys, database credentials, and environment configuration available to PHP;
- read or modify site content and user data;
- modify application files writable by the web-server account and establish persistence;
- access internal services reachable from the Craft host; or
- disrupt availability.
The exploit does not require allowAdminChanges, project-config modification, Kubernetes object access, environment-variable control, prior filesystem access, root privileges, poison injection from another system, or exploitation of an upstream dependency vulnerability.
Timeline
Hackrate
Our platform helps companies to identify software vulnerabilities in a cost-efficient way. It provides a secure and centralized view of ethical hacking projects for your company.
US Patent Applied for HackGATE #63/645,845
Products
From the Blog
-
Hackrate Ranked 1st in Hungary and 22nd Globally at Hack The Box’s Global Cyber Skills Benchmark 2026
May 29 • 13 min read
-
Press release: Hackrate becomes Hungary’s first CVE Numbering Authority
Jan 13 • 5 min read ★
-
Let 2026 be the year bug bounty becomes part of how you build and operate
Jan 05 • 4 min read