---
id: CVE-2026-105985
title: "Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action\_app/render-components.\n\n\n\nAny authenticated user with basic Control Panel access can submit request-controlled component classe…"
summary: "Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action\_app/render-components.\n\n\n\nAny authenticated user with basic Control Panel access can submit request-controlled component classe…"
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-1336
vendor: craftcms
product: craftcms/cms
affected:
  - craftcms/cms >= 5.0.0 < 5.11.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T11:17:16.857'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105985'
references:
  - url: 'https://github.com/craftcms/cms'
    label: 7004884b-51e2-48e8-b4a2-5ca29e80453e
  - url: 'https://github.com/craftcms/cms/releases/tag/5.11.0'
    label: 7004884b-51e2-48e8-b4a2-5ca29e80453e
  - url: 'https://github.com/craftcms/cms/security/advisories/GHSA-g48f-wc2q-4rrv'
    label: 7004884b-51e2-48e8-b4a2-5ca29e80453e
  - url: 'https://www.hckrt.com/hacktivity/HCKRT-PVWH7W'
    label: 7004884b-51e2-48e8-b4a2-5ca29e80453e
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-06T10:53:19.233279Z'
ingestedAt: '2026-10-06T10:55:47.406Z'
---

## Overview

Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components.



Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate().



This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process.



The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
