CVE-CVE-2026-44011
Severity
UNKNOWN
CVSS Score
0.0
Description
Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an input-handling flaw in a Yii object creation path that let any authenticated user inject malicious configuration and execute arbitrary commands on the server. The request-controlled condition field layouts data is converted into a live FieldLayout object without a Component::cleanseConfig() boundary. Because Craft configures models before parent::__construct(), attacker-controlled...
PoCs for CVE-CVE-2026-44011
CVE-2026-44011-craftcms-auth-rce
RCE
Python
0
4xura
2026-09-27
CVE-2026-44011-craft-rce-poc
RCE
Python
0
Cyberuser-hash
2026-09-27
CVE-2026-44011-poc
RCE
Python
0
DENNISDGR
2026-09-27