{"id":"CVE-2026-105985","title":"Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components.\n\n\n\nAny authenticated user with basic Control Panel access can submit request-controlled component classe…","summary":"Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components.\n\n\n\nAny authenticated user with basic Control Panel access can submit request-controlled component classe…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-1336"],"vendor":"craftcms","product":"craftcms/cms","affected":["craftcms/cms >= 5.0.0 < 5.11.0"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T11:17:16.857","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105985","references":[{"url":"https://github.com/craftcms/cms","label":"7004884b-51e2-48e8-b4a2-5ca29e80453e"},{"url":"https://github.com/craftcms/cms/releases/tag/5.11.0","label":"7004884b-51e2-48e8-b4a2-5ca29e80453e"},{"url":"https://github.com/craftcms/cms/security/advisories/GHSA-g48f-wc2q-4rrv","label":"7004884b-51e2-48e8-b4a2-5ca29e80453e"},{"url":"https://www.hckrt.com/hacktivity/HCKRT-PVWH7W","label":"7004884b-51e2-48e8-b4a2-5ca29e80453e"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-10-06T10:53:19.233279Z"},"ingestedAt":"2026-10-06T10:55:47.406Z","slug":"CVE-2026-105985","body":"## Overview\n\nCraft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components.\n\n\n\nAny authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate().\n\n\n\nThis render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process.\n\n\n\nThe issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}