CVE-2026-31857Disclosure(craftcms / craft_cms)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The BaseElementSelectConditionRule::getElementIds() method passes user-controlled string input through renderObjectTemplate() -- an unsandboxed Twig rendering function with escaping disabled. Any authenticated Control Panel user (including non-admin roles such as Author or Editor) can achieve full RCE by sending a crafted condition rule via standard element listing endpoints. This vulnerability requires no admin privileges, no special permissions beyond basic control panel access, and bypasses all production hardening settings (allowAdminChanges: false, devMode: false, enableTwigSandbox: true). Users should update to the patched 5.9.9 or 4.17.4 release to mitigate the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • craft_cms

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-12); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
craft_cms

2 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-12: 3Mentions · 2026-10-09: 1Technical Details · 2026-03-12: 303-1210-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets7 URLs
Full discourse4 posts
  • Rıdvan Yağlı@ridvanyagli

    🔴 Craft CMS'de yönetici yetkisi gerektirmeden sunucuda işletim sistemi komutları çalıştırmasına olanak sağlayan RCE Açığı: CVE-2026-31857 için PoC'ler yayınlandı. Craft CMS kontrol paneldeki relational condition mekanizmasında, kullanıcı kontrollü girdinin güvenli olmayan Twig şablonu olarak işlenmesinden kaynaklanan bir uzaktan kod çalıştırma (RCE) açığıdır. 🔴 Etkilenen sürümler: • Craft CMS 4: 4.17.3 ve öncesi • Craft CMS 5: 5.9.8 ve öncesi ✅ Düzeltilen sürümler: 4.17.4 ve 5.9.9 🔗 Advisory: https://github.com/craftcms/cms/security/advisories/GHSA-fp5j-j7j4-mcxc PoC'ler: https://github.com/0xTatsuki/CVE-2026-31857 https://github.com/WhiteMachin3/CVE-2026-31857 https://github.com/0Asylum/CVE-2026-31857

    01010292
    2.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-31857 Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The BaseElem… https://www.cve.org/CVERecord?id=CVE-2026-31857 ----- Traducción: CVE-2026-31857 Cra… http://infoflow.cloud`

    Post summary

    The tweet discloses a Remote Code Execution vulnerability in older versions of Craft CMS (prior to 5.9.9 and 4.17.4) and provides a link to the official CVE record.

    00000119
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31857 Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The BaseElem… https://www.cve.org/CVERecord?id=CVE-2026-31857

    Post summary

    A new RCE vulnerability in Craft CMS prior to version 5.9.9/4.17.4 has been disclosed with basic technical details, but no PoC, exploit, patch, or active exploitation information is provided.

    00000299
    56.7K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 CraftCMS, Remote Code Execution, #CVE-2026-31857 (High) https://dailycve.com/craftcms-remote-code-execution-cve-2026-31857-high/

    Post summary

    The message announces a new high‑severity remote code execution vulnerability in CraftCMS (CVE‑2026‑31857), providing only basic details.

    0000037
    167 followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
Appcraftcmscraft_cms---
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms5.0.0--
Appcraftcmscraft_cms5.0.0--

Explore more