CVE-2026-32264General(craftcms / craft_cms)

LOWCVSS 7.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, there is a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController. Craft control panel administrator permissions and allowAdminChanges must be enabled for this to work. This issue has been patched in versions 4.17.5 and 5.9.11.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-470

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • craft_cms

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
craft_cms

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-17: 3Technical Details · 2026-03-17: 103-17
Signal classification1 categories
General
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-32264 - craftcms - cms - https://www.redpacketsecurity.com/cve-alert-cve-2026-32264-craftcms-cms/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-32264 #craftcms #cms

    Post summary

    The text references CVE-2026-32264 for CraftCMS with a link, but provides no concrete details on exploitation, patching, or technical specifics.

    0000087
    3.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-32264 Behavior Injection Remote Code Execution in Craft CMS 4.0.0-RC1 to 4.17.4 and 5.0.0-RC1 to 5.9.10 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32264

    Post summary

    The statement notes CVE-2026-32264 as a behavior injection RCE affecting specified Craft CMS releases, but does not mention a PoC, exploit, patch, or active exploitation.

    0000051
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32264 Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, there is a Behavi… https://www.cve.org/CVERecord?id=CVE-2026-32264

    Post summary

    The post simply references a Craft CMS vulnerability with affected version ranges but offers no further technical details, PoC, patch information, or evidence of exploitation.

    00000113
    56.7K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appcraftcmscraft_cms---
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms5.0.0--
Appcraftcmscraft_cms5.0.0--

Explore more