What is CVE-2026-72778?
An authenticated Remote Code Execution vulnerability exists in the control panel's element-search condition handling in Craft CMS versions 4.0.0-RC1 through 4.18.2 and 5.0.0-RC1 through 5.10.6. The issue arises because Component::cleanseConfig() only sanitizes the outer request-controlled array. Immediate update to versions 4.18.2 or 5.10.6 is recommended.
Azərbaycanca: Craft CMS-in 4.0.0-RC1 - 4.18.2 və 5.0.0-RC1 - 5.10.6 versiyalarında idarə panelində "element-search condition" idarəetməsində autentifikasiya olunmuş Remote Code Execution (RCE) zəifliyi aşkarlanıb. Bu, "Component::cleanseConfig()" funksiyasının yalnız xarici massivi təmizləməsi nəticəsində yaranır. Dərhal 4.18.2 və ya 5.10.6 versiyalarına yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of Craft CMS are affected by CVE-2026-72778?
The vulnerability affects Craft CMS versions 4.0.0-RC1 through 4.18.2 and 5.0.0-RC1 through 5.10.6.
What is the recommended mitigation for CVE-2026-72778?
Immediate update to Craft CMS versions 4.18.2 or 5.10.6 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.