Improperly Controlled Modification of Dynamically-Determined Object Attributes in Craft CMS - #VU139963
Published: July 29, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the control panel element-search condition handling when processing a request containing a crafted condition.config JSON string. A remote user can send a specially crafted request to execute arbitrary code.
A valid control panel session and CSRF token are required. Command execution is semi-blind and may be confirmed through a server-side file-write side effect retrieved in a subsequent request.