Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate().
This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process.
The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components. Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate(). This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process. The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required. | |
| Title | Authenticated RCE via render-components Entry Type overrides | |
| First Time appeared |
Craftcms
Craftcms cms |
|
| Weaknesses | CWE-1336 | |
| CPEs | cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Craftcms
Craftcms cms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Hackrate
Published:
Updated: 2026-10-06T10:53:27.239Z
Reserved: 2026-10-06T10:08:10.713Z
Link: CVE-2026-105985
Updated: 2026-10-06T10:53:23.808Z
Status : Received
Published: 2026-10-06T11:17:16.857
Modified: 2026-10-06T11:17:16.857
Link: CVE-2026-105985
No data.
OpenCVE Enrichment
Updated: 2026-10-06T14:15:17Z