CVE-2026-25498Disclosure(craftcms / craft_cms)

LOWCVSS 7.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a Remote Code Execution (RCE) vulnerability exists in Craft CMS where the assembleLayoutFromPost() function in src/services/Fields.php fails to sanitize user-supplied configuration data before passing it to Craft::createObject(). This allows authenticated administrators to inject malicious Yii2 behavior configurations that execute arbitrary system commands on the server. This vulnerability represents an unpatched variant of the behavior injection vulnerability addressed in CVE-2025-68455, affecting different endpoints through a separate code path. This vulnerability is fixed in 5.8.22.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-470

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • craft_cms

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
craft_cms

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-09: 3Technical Details · 2026-02-09: 302-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25498: Crafting Chaos: RCE in Craft CMS via Yii2 Behavior Injection A high-severity Remote Code Execution (RCE) vulnerability exists in Craft CMS versions 4 and 5, specifically within the `assembleLayoutFromPost` method. The flaw stems from t... https://cvereports.com/reports/CVE-2026-25498

    Post summary

    High‑severity RCE vulnerability disclosed for Craft CMS 4/5 via Yii2 behavior injection, detailing the affected method but lacking PoC, exploit code, or patch information.

    0000051
    27 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25498 Remote Code Execution in Craft CMS via Unsanitized Configuration Data In... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25498 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A new RCE vulnerability (CVE-2026-25498) has been announced for Craft CMS, with a brief description and notification link provided but lacking PoC, exploit code, or patch details.

    0000047
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25498 Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a Remote Code Execution (RCE) vulnerability … https://www.cve.org/CVERecord?id=CVE-2026-25498

    Post summary

    The CVE-2026-25498 vulnerability in Craft platform allows remote code execution in versions 4.0.0‑RC1 through 4.16.17 and 5.0.0‑RC1 through 5.8.21, as detailed in the official CVE record.

    00000201
    56.5K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appcraftcmscraft_cms---
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms5.0.0--
Appcraftcmscraft_cms5.0.0--

Explore more