CVE-2026-44011Disclosure

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an input-handling flaw in a Yii object creation path that let any authenticated user inject malicious configuration and execute arbitrary commands on the server. The request-controlled condition field layouts data is converted into a live FieldLayout object without a Component::cleanseConfig() boundary. Because Craft configures models before parent::__construct(), attacker-controlled special config keys can take effect during object creation, and FieldLayout initialization then triggers a same-request event. This vulnerability is fixed in 4.17.12 and 5.9.18.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-479

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-12); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-14: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-14: 105-1205-14
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-121
Disclosure1
2026-05-141
PoC1
Full discourse2 posts
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #CraftCMS: disponibili #PoC per lo sfruttamento delle CVE-2026-44010 e CVE-2026-44011 Rischio: 🔴 Tipologia 🔸 Remote Code Execution 🔸 Information Disclosure 🔗 https://www.acn.gov.it/portale/en/w/craft-cms-disponibili-poc-per-lo-sfruttamento-delle-cve-2026-44010-e-cve-2026-44011 ⚠ Importante aggiornare i software interessati https://t.co/grmfBND2RE

    Post summary

    The tweet announces publicly available Proof of Concept code for CraftCMS CVE‑2026‑44010 and CVE‑2026‑44011, highlights remote code execution and information disclosure risks, and urges users to update affected software.

    00000211
    611 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44011 Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an input-handling flaw in a Yii object creation path… https://www.cve.org/CVERecord?id=CVE-2026-44011

    Post summary

    CVE-2026-44011 reveals an input‑handling flaw in the Yii object creation path of Craft CMS versions 4.0.0–4.17.11 and 5.9.18. No patches, exploits, or active exploitation details are provided in the text.

    00000112
    57.5K followersView on X

Explore more