---
id: CVE-2026-72778
title: >-
  Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before
  5.10.6 contain an authenticated remote code execution vulnerability in the
  control panel element-search condition handling
summary: >-
  Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before
  5.10.6 contain an authenticated remote code execution vulnerability in the
  control panel element-search condition handling. Craft cleanses the outer
  request-contro…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-915
vendor: craftcms
product: cms
affected:
  - cms >= 5.0.0-RC1 < 5.10.6
  - cms >= 4.0.0-RC1 < 4.18.2
published: '2026-08-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:34.307'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72778'
references:
  - url: 'https://github.com/craftcms/cms/security/advisories/GHSA-265m-7826-wjqm'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/craft-cms-rc1-before-authenticated-rce-via-condition-config
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-14T19:52:54.520965Z'
epss: 0.00803
epssPercentile: 0.55354
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/TRX-0/CVE-2026-72778-craftcms-rce'
  checkedAt: '2026-10-08T16:52:49.776Z'
exploitAvailable: true
ingestedAt: '2026-10-08T16:52:14.712Z'
---

## Overview

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. Craft cleanses the outer request-controlled condition array via Component::cleanseConfig(), but Conditions::createCondition() later decodes and merges the JSON string in condition.config without re-running cleanseConfig() on the decoded configuration. Because condition.config is a JSON string during the first cleanse, Yii special config keys such as 'as ...' and 'on ...' can be hidden inside it and, after JSON decoding, are interpreted by Yii as behavior/event configuration during FieldLayout object creation. An attacker with an authenticated control panel session (and a valid CSRF token) can exploit this to execute operating system commands as the PHP/web user.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
