CVE-2026-32267Disclosure(craftcms / craft_cms)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch craftcms craft_cms systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their privileges to admin by abusing UsersController->actionImpersonateWithToken. This issue has been patched in versions 4.17.6 and 5.9.12.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • craft_cms

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-03-17); latest day: 2
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
craft_cms

2 versions affected across 1 product

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-03-16: 1Mentions · 2026-03-17: 3Mentions · 2026-03-18: 2Mentions · 2026-03-26: 2PoC Mentioned / Linked · 2026-03-16: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 2Technical Details · 2026-03-18: 2Technical Details · 2026-03-26: 203-1603-1703-1803-26
Signal classification3 categories
Disclosure
675.0%
General
112.5%
Patch
112.5%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-161
Disclosure1
2026-03-173
Disclosure2General1
2026-03-182
Disclosure1Patch1
2026-03-262
Disclosure2
Full discourse8 posts
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-32267: Vulnerability Alert Critical Remote Code Execution via Deserialization Gadget Chain! An attacker supplies a maliciously crafted serialized PHP object in a user-controllable field (e.g., cookie or POST parameter) that triggers unsafe deserialization in CraftCMS’s custom YAML/PHP unserializer, leading to arbitrary code execution when gadget chains invoke __wakeup() or __destruct() methods. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-32267 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-32267" Search Dork: app="CraftCMS" Exposure: 105k+ instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJDcmFmdENNUyI=&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260326 #CVE #CraftCMS #RCE #Deserialization #WebSecurity #DarkEye

    Post summary

    A critical RCE vulnerability (CVE‑2026‑32267) in CraftCMS’s YAML/PHP unserializer has been disclosed with detailed technical specifics, but no PoC, exploit, active exploitation, or patch information is provided.

    012030153.0K
    12.1K followersView on X
  • DarkEye@darkeye_team
    Disclosure

    🚨 Detailed Analysis for CVE-2026-32267 (Vulnerability Alert) Stop guessing the risk. The technical details are ready. 🔥 $5 Special Trial to celebrate our CVE Feed launch! Get the Analysis & Prioritized Asset List now: 🔗 https://www.darkeye.org/vuln/cve/CVE-2026-32267 Critical Unauthenticated RCE! Exploits insecure deserialization in Craft CMS's GraphQL API to execute arbitrary PHP code without authentication. cc: @zoomeye_team (105k+ targets detected 🎯 (Early Warning)) #CVE-2026-32267 #CraftCMS #RCE #DarkEye #ZoomEye #BugBounty

    Post summary

    The post provides a technical disclosure of a critical unauthenticated RCE in Craft CMS via insecure deserialization, without linking a PoC, exploit code, or evidence of active exploitation.

    00030199
    957 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Craft CMS patches CVE-2026-32267, a 7.7 CVSS flaw where a simple Live Preview token grants low-privilege users full admin access. Update today. #CraftCMS #CVE #CyberSecurity #InfoSec #PrivilegeEscalation #Vulnerability #PatchAlert #WebSecurity https://securityonline.info/skeleton-key-live-preview-critical-craft-cms-flaw-grants-admin-access/ https://t.co/6WoMe0sf51

    Post summary

    Craft CMS has released a patch for CVE-2026-32267, a low‑privilege escalation flaw via Live Preview token, urging users to update immediately.

    00010311
    10.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32267 - Critical Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenti... https://www.thehackerwire.com/vulnerability/CVE-2026-32267/ https://t.co/NoaHATIUmu

    Post summary

    Disclosed CVE-2026-32267, a critical flaw in Craft CMS versions 4.x through 4.17.5 and 5.x through 5.9.11, that allows low‑privilege or unauthenticated users to exploit a vulnerability.

    0000072
    138 followersView on X
  • PulsePatch.io@pulsepatchio
    General

    A privilege escalation flaw (CVE-2026-32267) affects `Craft CMS` via its impersonation function. This could allow unauthorized access. System administrators should monitor for official updates. #CraftCMS #InfoSec #Vulnerability https://www.pulsepatch.io/posts/cve-2026-32267-craft-cms-privilege-escalation

    Post summary

    The post alerts that CVE‑2026‑32267 is a privilege escalation vulnerability in Craft CMS’s impersonation function and advises admins to watch for official patch releases.

    0000078
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32267 Privilege Escalation Vulnerability in Craft CMS via Imper... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32267 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces a new privilege‑escalation flaw in Craft CMS, citing CVE-2026-32267 and linking to a vulnerability detail page, but offers limited technical or patch information.

    0000052
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32267 Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege u… https://www.cve.org/CVERecord?id=CVE-2026-32267

    Post summary

    The post references CVE‑2026‑32267 and lists affected Craft CMS versions, but lacks PoC, exploit details, patch information, or deeper technical context.

    0000089
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32267: Craft... Token-based impersonation bypass in Craft CMS lets any low-priv user instantly become admin - shared URLs become admin shells. #CraftCMS #PrivEsc. https://zerodaysignal.com/vulnerability/CVE-2026-32267 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a token‑based impersonation flaw in Craft CMS (CVE‑2026‑32267) that allows low‑priv users to gain admin rights through shared URLs, with a link pointing to further details.

    0000090
    151 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appcraftcmscraft_cms---
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms5.0.0--
Appcraftcmscraft_cms5.0.0--

Explore more